openSSL punycode Vulnerability

Is dSPACE software affected by the openSSL punycode vulnerabilities?

We are getting requests from our customers who are concerned about the so-called openSSL punycode vulnerabilities.

The security vulnerabilities are related to openSSL library, a C-based open-source library for encryption of data in multiple environments.

Based on our software dependency analysis, following dSPACE products contain openSSL versions with the below listed vulnerabilities

  • SIMPHERA

An update of the library which fixes these vulnerabilities will be available in SIMPHERA 22.9.

                                                                                                                                             
CVE Dictionary Entry Description and assessment
            

CVE-2022-3602

            
            

This buffer overflow vulnerability could lead to crash in the affected products causing a denial of service or potentially remote code execution. Affected openSSL versions are 3.0.0-3.0.6.

            
            

 CVE-2022-3786

            
            

This buffer overflow vulnerability could lead to crash in the affected products causing a denial of service. Affected openSSL versions are 3.0.0-3.0.6.

            

Tags
Date 2022-11-07
인포메이션 타입 알림
인포메이션 카테고리 Product Security, Troubleshooting
dSPACE Release 2022-A, 2021-B, 2021-A, 2020-B, 2020-A, 2019-B, 2019-A, 2018-B, 2018-A, 2017-B, 2017-A, 2016-B, 2016-A, 2015-B, 2015-A, 2014-B, 2014-A, 2013-B, 2013-A, Prior to 2013-A

dSPACE direct 뉴스레터 서비스를 통해 최신 소식을 받아보세요.

dSPACE 뉴스레터 서비스를 통해 최신 use case 와 신규 솔루션 및 제품, 교육 및 이벤트에 대한 정보를 지속적으로 확인하세요. 여기에서 무료 로구독을 신청하세요.

Enable form call

At this point, an input form from Click Dimensions is integrated. This enables us to process your newsletter subscription. The form is currently hidden due to your privacy settings for our website.

External input form

By activating the input form, you consent to personal data being transmitted to Click Dimensions within the EU, in the USA, Canada or Australia. More on this in our privacy policy.