Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities BSI Germany

[UPDATE] [mittel] OpenSSL: Schwachstelle ermöglicht Codeausführung, Datenmanipulation, Offenlegung von Informationen und Dos

A vulnerability in OpenSSL (CVSS Base Score 7.4) allows an attacker to execute arbitrary code, cause a denial of service, disclose sensitive information, and manipulate data. The flaw affects OpenSSL versions prior to 3.3.1, 3.2.2, 3.1.6, 3.0.14, and 1.1.1y, requiring an upgrade to these respective fixed versions. The article notes that a mitigation is available but does not specify the workaround details.
Read Full Article →

[WID-SEC-2024-1240] OpenSSL: Schwachstelle ermöglicht Codeausführung, Datenmanipulation, Offenlegung von Informationen und Dos CVSS Base Score 7.4 (hoch) CVSS Temporal Score 6.4 (mittel) Remoteangriff nein Datum 28.05.2024 Stand UPDATE 17.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung OpenSSL ist eine im Quelltext frei verfügbare Bibliothek, die Secure Sockets Layer (SSL) und Transport Layer Security (TLS) implementiert. Produkte UPDATE 16.06.2026 Oracle Linux RESF Rocky Linux UPDATE 17.12.2025 Broadcom Fabric OS NetApp ActiveIQ Unified Manager for Linux NetApp AFF Baseboard Management Controller NetApp ActiveIQ Unified Manager for VMware vSphere NetApp FAS Baseboard Management Controller UPDATE 06.08.2025 IBM App Connect Enterprise <LTS 12.0.14 UPDATE 29.06.2025 IBM Cognos Analytics <12.0.4 FP1 IBM Cognos Analytics <11.2.4 FP6 UPDATE 22.05.2025 HPE NonStop Server UPDATE 09.04.2025 Dell BIOS Dell Computer IBM Spectrum Protect Plus <10.1.17 UPDATE 30.03.2025 IBM InfoSphere Information Server 11.7 UPDATE 10.03.2025 IBM Security Guardium 12.0 IBM Rational ClearQuest <10.0.7 IBM Rational ClearQuest <Fix Pack 8 (9.1.0.8) for 9.1 UPDATE 04.03.2025 IBM Rational ClearCase <9.1.0.8 IBM Rational ClearCase <10.0.1.3 IBM Rational ClearCase <11.0.0.3 UPDATE 14.01.2025 Red Hat OpenShift Logging <5.9.10 UPDATE 12.01.2025 Xerox FreeFlow Print Server v9 for Solaris UPDATE 08.12.2024 IBM MQ UPDATE 14.11.2024 HPE HP-UX OpenSSL Software <A.03.00.15.001 UPDATE 12.11.2024 Insyde UEFI Firmware <RV24.06.3 Insyde UEFI Firmware <RV23.08.1 UPDATE 11.11.2024 Red Hat Enterprise Linux UPDATE 30.10.2024 Debian Linux UPDATE 13.10.2024 IBM Rational Build Forge <8.0.0.27 UPDATE 16.09.2024 Hitachi Command Suite Hitachi Ops Center Hitachi Configuration Manager UPDATE 14.08.2024 Securepoint UTM <12.7.2 UPDATE 13.08.2024 Amazon Linux 2 UPDATE 05.08.2024 EMC Avamar Dell NetWorker UPDATE 31.07.2024 Ubuntu Linux UPDATE 30.07.2024 IBM VIOS 3.1 IBM AIX 7.3 IBM VIOS 4.1 IBM AIX 7.2 UPDATE 23.07.2024 Meinberg LANTIME <V7.08.014 UPDATE 17.06.2024 Fedora Linux UPDATE 13.06.2024 SUSE Linux 28.05.2024 Open Source OpenSSL <3.3.1 Open Source OpenSSL <3.2.2 Open Source OpenSSL <3.1.6 Open Source OpenSSL <3.0.14 Open Source OpenSSL <1.1.1y Angriff Angriff Ein entfernter anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen und Daten zu manipulieren. CVE Informationen Versionshistorie Feedback zum Advisory geben

Share this article