[Git][security-tracker-team/security-tracker][master] Process some more NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 14 21:43:08 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
48ac8c10 by Salvatore Bonaccorso at 2021-09-14T22:41:56+02:00
Process some more NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1595,13 +1595,13 @@ CVE-2021-40359
 CVE-2021-40358
 	RESERVED
 CVE-2021-40357 (A vulnerability has been identified in Teamcenter Active Workspace V4. ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-40356 (A vulnerability has been identified in Teamcenter V12.4 (All versions  ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-40355 (A vulnerability has been identified in Teamcenter V12.4 (All versions  ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-40354 (A vulnerability has been identified in Teamcenter V12.4 (All versions  ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-3761 (Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitt ...)
 	TODO: check
 CVE-2021-3760
@@ -3682,7 +3682,7 @@ CVE-2021-39393
 CVE-2021-39392
 	RESERVED
 CVE-2021-39391 (Cross Site Scripting (XSS) vulnerability exists in the admin panel in  ...)
-	TODO: check
+	NOT-FOR-US: Beego
 CVE-2021-39390
 	RESERVED
 CVE-2021-39389
@@ -6549,7 +6549,7 @@ CVE-2021-38178
 CVE-2021-38177 (SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null poin ...)
 	NOT-FOR-US: SAP
 CVE-2021-38176 (Due to improper input sanitization, an authenticated user with certain ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2021-38175 (SAP Analysis for Microsoft Office - version 2.8, allows an attacker wi ...)
 	NOT-FOR-US: SAP
 CVE-2021-38174 (When a user opens manipulated files received from untrusted sources in ...)
@@ -8796,19 +8796,19 @@ CVE-2021-37208
 CVE-2021-37207
 	RESERVED
 CVE-2021-37206 (A vulnerability has been identified in SIPROTEC 5 relays with CPU vari ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37205
 	RESERVED
 CVE-2021-37204
 	RESERVED
 CVE-2021-37203 (A vulnerability has been identified in NX 1980 Series (All versions &l ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37202 (A vulnerability has been identified in NX 1980 Series (All versions &l ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37201 (A vulnerability has been identified in SINEC NMS (All versions < V1 ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37200 (A vulnerability has been identified in SINEC NMS (All versions < V1 ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37199
 	RESERVED
 CVE-2021-37198
@@ -8822,13 +8822,13 @@ CVE-2021-37195
 CVE-2021-37194
 	RESERVED
 CVE-2021-37193 (A vulnerability has been identified in SINEMA Remote Connect Server (A ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37192 (A vulnerability has been identified in SINEMA Remote Connect Server (A ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37191 (A vulnerability has been identified in SINEMA Remote Connect Server (A ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37190 (A vulnerability has been identified in SINEMA Remote Connect Server (A ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37189
 	RESERVED
 CVE-2021-37188
@@ -8836,13 +8836,13 @@ CVE-2021-37188
 CVE-2021-37187
 	RESERVED
 CVE-2021-37186 (A vulnerability has been identified in LOGO! CMR2020 (All versions &lt ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37185
 	RESERVED
 CVE-2021-37184 (A vulnerability has been identified in Industrial Edge Management (All ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37183 (A vulnerability has been identified in SINEMA Remote Connect Server (A ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37182
 	RESERVED
 CVE-2021-37181 (A vulnerability has been identified in Cerberus DMS V4.0 (All versions ...)
@@ -8856,7 +8856,7 @@ CVE-2021-37178 (A vulnerability has been identified in Solid Edge SE2021 (All Ve
 CVE-2021-37177 (A vulnerability has been identified in SINEMA Remote Connect Server (A ...)
 	TODO: check
 CVE-2021-37176 (A vulnerability has been identified in Simcenter Femap V2020.2 (All ve ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-37175 (A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versi ...)
 	TODO: check
 CVE-2021-37174 (A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versi ...)
@@ -10244,9 +10244,9 @@ CVE-2021-36584 (An issue was discovered in GPAC 1.0.1. There is a heap-based buf
 CVE-2021-36583
 	RESERVED
 CVE-2021-36582 (In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g.,  ...)
-	TODO: check
+	NOT-FOR-US: Kooboo CMS
 CVE-2021-36581 (Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possib ...)
-	TODO: check
+	NOT-FOR-US: Kooboo CMS
 CVE-2021-36580
 	RESERVED
 CVE-2021-36579
@@ -16856,7 +16856,7 @@ CVE-2021-3567
 CVE-2021-33738 (A vulnerability has been identified in JT2Go (All versions < V13.2. ...)
 	NOT-FOR-US: JT2Go
 CVE-2021-33737 (A vulnerability has been identified in SIMATIC CP 343-1 (incl. SIPLUS  ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-33736
 	RESERVED
 CVE-2021-33735
@@ -16890,15 +16890,15 @@ CVE-2021-33722
 CVE-2021-33721 (A vulnerability has been identified in SINEC NMS (All versions < V1 ...)
 	NOT-FOR-US: Siemens
 CVE-2021-33720 (A vulnerability has been identified in SIPROTEC 5 relays with CPU vari ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-33719 (A vulnerability has been identified in SIPROTEC 5 relays with CPU vari ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-33718 (A vulnerability has been identified in Mendix Applications using Mendi ...)
 	NOT-FOR-US: Mendix Applications
 CVE-2021-33717 (A vulnerability has been identified in JT2Go (All versions < V13.2. ...)
 	NOT-FOR-US: JT2Go
 CVE-2021-33716 (A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2021-33715 (A vulnerability has been identified in JT Utilities (All versions < ...)
 	NOT-FOR-US: Siemens
 CVE-2021-33714 (A vulnerability has been identified in JT Utilities (All versions < ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/48ac8c104023ce0b3e4762f02b0f1be7f6fbdc3c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/48ac8c104023ce0b3e4762f02b0f1be7f6fbdc3c
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210914/a38e73ba/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list