{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Public",
      "tlp": {
        "label": "WHITE"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "description",
        "text": "Two vulnerabilities affecting StationGuard (CVE-2026-16315 and CVE-2026-16316) versions before 4.10 could allow attackers to either bypass authentication through a timing side-channel and gain unauthorized administrative access, or disrupt IEC 61850 Sampled Values alert processing by crashing a protocol-handling process with crafted traffic.",
        "title": "StationGuard"
      },
      {
        "category": "description",
        "text": "The StationScout vulnerability CVE-2026-16731 affects versions before 3.05 and could allow unauthenticated attackers to exploit a cryptographic timing side-channel in backend authentication to forge credentials, bypass authorization, and gain unauthorized control of system settings or inject network traffic.",
        "title": "StationScout"
      },
      {
        "category": "description",
        "text": "StationGuard and StationScout are affected by multiple Linux kernel vulnerabilities in netfilter and socket handling. An attacker could exploit these issues using crafted network traffic to trigger denial-of-service conditions, including resource exhaustion, persistent memory leaks, and out-of-bounds reads.",
        "title": "Linux Kernel"
      },
      {
        "category": "description",
        "text": "Two Node.js vulnerabilities affecting StationGuard and StationScout could result in remote denial-of-service attacks by triggering V8 hash-collision complexity issues or HTTP/2 memory leaks that exhaust available resources.",
        "title": "Node.js"
      },
      {
        "category": "other",
        "text": "OMICRON is an international company that works passionately on ideas for making electric power systems safe, secure and reliable. Our pioneering solutions are designed to meet our industry\u2019s current and future challenges. We always go the extra mile to empower our customers: we react to their needs, provide extraordinary local support, and share our expertise. Within the OMICRON group, we research and develop innovative technologies for all fields in electric power systems. When it comes to electrical testing for medium- and high-voltage equipment, protection testing, digital substation testing solutions, and cybersecurity solutions, customers all over the world trust in the accuracy, speed, and quality of our user-friendly solutions.",
        "title": "About OMICRON electronics"
      },
      {
        "category": "other",
        "text": "OMICRON has released StationGuard 4.10 (with firmware version 4.10.0136) and StationScout 3.05 (with firmware version 3.05.0081) which address the issues and fix the vulnerabilities.",
        "title": "Mitigation"
      },
      {
        "category": "other",
        "text": "It is strongly recommended that customers currently using the affected versions install the latest update available on the customer portal (registration required) as soon as possible to ensure the security of their system. \n\nMore information about StationGuard, including the download links, can be found on \nhttps://www.omicronenergy.com/en/products/stationguard.\n\nFor StationScout the information can be found on \nhttps://www.omicronenergy.com/en/products/stationscout.",
        "title": "Required Actions"
      },
      {
        "category": "other",
        "text": "StationGuard before 4.10@https://www.omicronenergy.com/en/products/stationguard/;StationScout before 3.05@https://www.omicronenergy.com/en/products/stationscout/",
        "title": "Simplified affected products list included for external usage"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "product.security@omicronenergy.com",
      "name": "OMICRON Product Security Team",
      "namespace": "https://www.omicronenergy.com/security/"
    },
    "references": [
      {
        "category": "self",
        "summary": "OSA-21 TODO - PDF File",
        "url": "https://www.omicronenergy.com/.well-known/csaf/osa-21.pdf"
      },
      {
        "category": "self",
        "summary": "OSA-21 TODO - TXT File",
        "url": "https://www.omicronenergy.com/.well-known/csaf/osa-21.txt"
      },
      {
        "category": "self",
        "summary": "OSA-21 TODO - CSAF File",
        "url": "https://www.omicronenergy.com/.well-known/csaf/osa-21.json"
      },
      {
        "summary": "StationGuard Product Page",
        "url": "https://www.omicronenergy.com/en/products/stationguard/"
      },
      {
        "summary": "StationScout Product Page",
        "url": "https://www.omicronenergy.com/en/products/stationscout/"
      }
    ],
    "title": "OSA-21: StationGuard & StationScout Vulnerabilities",
    "tracking": {
      "current_release_date": "2026-08-05T11:00:00.000Z",
      "generator": {
        "date": "2026-08-04T07:01:01.947Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.5.20"
        }
      },
      "id": "OSA-21",
      "initial_release_date": "2026-08-05T11:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-08-05T11:00:00.000Z",
          "number": "1.0.0",
          "summary": "Initial publication"
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "<=4.00.0124",
                    "product": {
                      "name": "StationGuard Firmware 4.00.0124 and before",
                      "product_id": "PUC-SGI_4.00_and_before"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "4.00.0124",
                    "product": {
                      "name": "StationGuard Firmware 4.00.0124",
                      "product_id": "PUC-SGI_4.00"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "4.10.0136",
                    "product": {
                      "name": "StationGuard Firmware 4.10.0136",
                      "product_id": "PUC-SGI_4.10"
                    }
                  }
                ],
                "category": "product_name",
                "name": "StationGuard Firmware"
              }
            ],
            "category": "product_name",
            "name": "StationGuard"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "<=3.00.0079",
                    "product": {
                      "name": "StationScout Firmware 3.00.0079 and before",
                      "product_id": "PUC-SSI_3.00_and_before"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "3.00.0080",
                    "product": {
                      "name": "StationScout Firmware 3.00.0080",
                      "product_id": "PUC-SSI_3.05"
                    }
                  }
                ],
                "category": "product_name",
                "name": "StationScout Firmware"
              }
            ],
            "category": "product_name",
            "name": "StationScout"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "MBX1",
                "product": {
                  "name": "MBX1",
                  "product_id": "MBX1"
                }
              },
              {
                "category": "product_name",
                "name": "MBX2",
                "product": {
                  "name": "MBX2",
                  "product_id": "MBX2"
                }
              },
              {
                "category": "product_name",
                "name": "RBX1",
                "product": {
                  "name": "RBX1",
                  "product_id": "RBX1"
                }
              },
              {
                "category": "product_name",
                "name": "VBX1",
                "product": {
                  "name": "VBX1",
                  "product_id": "VBX1"
                }
              }
            ],
            "category": "product_family",
            "name": "*BX Platform"
          }
        ],
        "category": "vendor",
        "name": "OMICRON electronics"
      }
    ],
    "relationships": [
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "MBX1 with StationGuard Firmware 4.00.0124 and before",
          "product_id": "PUC-MBX1-SGI_4.00_and_before"
        },
        "product_reference": "PUC-SGI_4.00_and_before",
        "relates_to_product_reference": "MBX1"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "MBX2 with StationGuard Firmware 4.00.0124 and before",
          "product_id": "PUC-MBX2-SGI_4.00_and_before"
        },
        "product_reference": "PUC-SGI_4.00_and_before",
        "relates_to_product_reference": "MBX2"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "RBX1 with StationGuard Firmware 4.00.0124 and before",
          "product_id": "PUC-RBX1-SGI_4.00_and_before"
        },
        "product_reference": "PUC-SGI_4.00_and_before",
        "relates_to_product_reference": "RBX1"
      },
      {
        "category": "installed_on",
        "relates_to_product_reference": "VBX1",
        "product_reference": "PUC-SGI_4.00_and_before",
        "full_product_name": {
          "name": "VBX1 with StationGuard Firmware 4.00.0124 and before",
          "product_id": "PUC-VBX1-SGI_4.00_and_before"
        }
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "MBX1 with StationGuard Firmware 4.00.0124",
          "product_id": "PUC-MBX1-SGI_4.00"
        },
        "product_reference": "PUC-SGI_4.00",
        "relates_to_product_reference": "MBX1"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "MBX2 with StationGuard Firmware 4.00.0124",
          "product_id": "PUC-MBX2-SGI_4.00"
        },
        "product_reference": "PUC-SGI_4.00",
        "relates_to_product_reference": "MBX2"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "RBX1 with StationGuard Firmware 4.00.0124",
          "product_id": "PUC-RBX1-SGI_4.00"
        },
        "product_reference": "PUC-SGI_4.00",
        "relates_to_product_reference": "RBX1"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "VBX1 with StationGuard Firmware 4.00.0124",
          "product_id": "PUC-VBX1-SGI_4.00"
        },
        "product_reference": "PUC-SGI_4.00",
        "relates_to_product_reference": "VBX1"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "MBX1 with StationGuard Firmware 4.10.0136",
          "product_id": "PUC-MBX1-SGI_4.10"
        },
        "product_reference": "PUC-SGI_4.10",
        "relates_to_product_reference": "MBX1"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "MBX2 with StationGuard Firmware 4.10.0136",
          "product_id": "PUC-MBX2-SGI_4.10"
        },
        "product_reference": "PUC-SGI_4.10",
        "relates_to_product_reference": "MBX2"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "RBX1 with StationGuard Firmware 4.10.0136",
          "product_id": "PUC-RBX1-SGI_4.10"
        },
        "product_reference": "PUC-SGI_4.10",
        "relates_to_product_reference": "RBX1"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "VBX1 with StationGuard Firmware 4.10.0136",
          "product_id": "PUC-VBX1-SGI_4.10"
        },
        "product_reference": "PUC-SGI_4.10",
        "relates_to_product_reference": "VBX1"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "MBX1 with StationScout Firmware 3.00.0079 and before",
          "product_id": "PUC-MBX1-SSI_3.00_and_before"
        },
        "product_reference": "PUC-SSI_3.00_and_before",
        "relates_to_product_reference": "MBX1"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "MBX2 with StationScout Firmware 3.00.0079 and before",
          "product_id": "PUC-MBX2-SSI_3.00_and_before"
        },
        "product_reference": "PUC-SSI_3.00_and_before",
        "relates_to_product_reference": "MBX2"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "RBX1 with StationScout Firmware 3.00.0079 and before",
          "product_id": "PUC-RBX1-SSI_3.00_and_before"
        },
        "product_reference": "PUC-SSI_3.00_and_before",
        "relates_to_product_reference": "RBX1"
      },
      {
        "category": "installed_on",
        "relates_to_product_reference": "VBX1",
        "product_reference": "PUC-SSI_3.00_and_before",
        "full_product_name": {
          "name": "VBX1 with StationScout Firmware 3.00.0079 and before",
          "product_id": "PUC-VBX1-SSI_3.00_and_before"
        }
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "MBX1 with StationScout Firmware 3.00.0080",
          "product_id": "PUC-MBX1-SSI_3.05"
        },
        "product_reference": "PUC-SSI_3.05",
        "relates_to_product_reference": "MBX1"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "MBX2 with StationScout Firmware 3.00.0080",
          "product_id": "PUC-MBX2-SSI_3.05"
        },
        "product_reference": "PUC-SSI_3.05",
        "relates_to_product_reference": "MBX2"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "RBX1 with StationScout Firmware 3.00.0080",
          "product_id": "PUC-RBX1-SSI_3.05"
        },
        "product_reference": "PUC-SSI_3.05",
        "relates_to_product_reference": "RBX1"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "VBX1 with StationScout Firmware 3.00.0080",
          "product_id": "PUC-VBX1-SSI_3.05"
        },
        "product_reference": "PUC-SSI_3.05",
        "relates_to_product_reference": "VBX1"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-16315",
      "cwe": {
        "id": "CWE-208",
        "name": "Observable Timing Discrepancy"
      },
      "notes": [
        {
          "category": "summary",
          "text": "OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients.\nAn attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters."
        }
      ],
      "product_status": {
        "fixed": [
          "PUC-MBX1-SGI_4.10",
          "PUC-MBX2-SGI_4.10",
          "PUC-RBX1-SGI_4.10",
          "PUC-VBX1-SGI_4.10"
        ],
        "known_affected": [
          "PUC-MBX1-SGI_4.00_and_before",
          "PUC-MBX2-SGI_4.00_and_before",
          "PUC-RBX1-SGI_4.00_and_before",
          "PUC-VBX1-SGI_4.00_and_before"
        ]
      },
      "references": [
        {
          "summary": "CVE-2026-16315",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16315"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "CHANGED",
            "integrityImpact": "HIGH",
            "availabilityImpact": "NONE",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "exploitCodeMaturity": "UNPROVEN",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "temporalScore": 7.6,
            "confidentialityImpact": "HIGH",
            "temporalSeverity": "HIGH",
            "environmentalScore": 7.6,
            "environmentalSeverity": "HIGH"
          },
          "products": [
            "PUC-MBX1-SGI_4.00_and_before",
            "PUC-MBX2-SGI_4.00_and_before",
            "PUC-RBX1-SGI_4.00_and_before",
            "PUC-VBX1-SGI_4.00_and_before"
          ]
        }
      ],
      "title": "Authentication and authorization bypass via cryptographic timing side-channel attack in StationGuard"
    },
    {
      "cve": "CVE-2026-16316",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "summary",
          "text": "OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The vulnerability does not affect overall system availability or the processing of other traffic types, and the process is automatically restarted, and the failure is immediately reported to the user."
        }
      ],
      "product_status": {
        "fixed": [
          "PUC-MBX1-SGI_4.10",
          "PUC-MBX2-SGI_4.10",
          "PUC-RBX1-SGI_4.10",
          "PUC-VBX1-SGI_4.10"
        ],
        "known_affected": [
          "PUC-MBX1-SGI_4.00",
          "PUC-MBX2-SGI_4.00",
          "PUC-RBX1-SGI_4.00",
          "PUC-VBX1-SGI_4.00"
        ]
      },
      "references": [
        {
          "summary": "CVE-2026-16316",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16316"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C",
            "attackVector": "ADJACENT_NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "integrityImpact": "NONE",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "exploitCodeMaturity": "UNPROVEN",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "temporalScore": 3.8,
            "confidentialityImpact": "NONE",
            "temporalSeverity": "LOW",
            "environmentalScore": 3.8,
            "environmentalSeverity": "LOW"
          },
          "products": [
            "PUC-MBX1-SGI_4.00_and_before",
            "PUC-MBX2-SGI_4.00_and_before",
            "PUC-RBX1-SGI_4.00_and_before",
            "PUC-VBX1-SGI_4.00_and_before"
          ]
        }
      ],
      "title": "Malformed IEC 61850 Sampled Values frames cause partial denial of service in StationGuard"
    },
    {
      "cve": "CVE-2026-16731",
      "cwe": {
        "id": "CWE-208",
        "name": "Observable Timing Discrepancy"
      },
      "notes": [
        {
          "category": "summary",
          "text": "OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients.\nAn attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters or injecting network traffic into the connected network."
        }
      ],
      "product_status": {
        "fixed": [
          "PUC-MBX1-SSI_3.05",
          "PUC-MBX2-SSI_3.05",
          "PUC-RBX1-SSI_3.05",
          "PUC-VBX1-SSI_3.05"
        ],
        "known_affected": [
          "PUC-MBX1-SSI_3.00_and_before",
          "PUC-MBX2-SSI_3.00_and_before",
          "PUC-RBX1-SSI_3.00_and_before",
          "PUC-VBX1-SSI_3.00_and_before"
        ]
      },
      "references": [
        {
          "summary": "CVE-2026-16731",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16731"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C",
            "attackVector": "ADJACENT_NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "integrityImpact": "NONE",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "exploitCodeMaturity": "UNPROVEN",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "temporalScore": 3.8,
            "confidentialityImpact": "NONE",
            "temporalSeverity": "LOW",
            "environmentalScore": 3.8,
            "environmentalSeverity": "LOW"
          },
          "products": [
            "PUC-MBX1-SGI_4.00_and_before",
            "PUC-MBX2-SGI_4.00_and_before",
            "PUC-RBX1-SGI_4.00_and_before",
            "PUC-VBX1-SGI_4.00_and_before"
          ]
        }
      ],
      "title": "Authentication and authorization bypass via cryptographic timing side-channel attack in StationScout"
    },
    {
      "cve": "CVE-2026-23139",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "summary",
          "text": "The `netfilter` component in the Linux kernel is vulnerable to a denial-of-service (DoS) issue due to improper handling of the `last_gc` value in the `nf_conncount` functionality. This vulnerability arises because the `last_gc` value is updated even when garbage collection (GC) is not performed, allowing an attacker to exploit a high packet rate to bypass GC and cause the connection list to grow indefinitely. This could allow an attacker to exhaust system resources, leading to a potential denial of service."
        }
      ],
      "product_status": {
        "fixed": [
          "PUC-MBX1-SSI_3.05",
          "PUC-MBX2-SSI_3.05",
          "PUC-RBX1-SSI_3.05",
          "PUC-VBX1-SSI_3.05",
          "PUC-MBX1-SGI_4.10",
          "PUC-MBX2-SGI_4.10",
          "PUC-RBX1-SGI_4.10",
          "PUC-VBX1-SGI_4.10"
        ],
        "known_affected": [
          "PUC-MBX1-SSI_3.00_and_before",
          "PUC-MBX2-SSI_3.00_and_before",
          "PUC-RBX1-SSI_3.00_and_before",
          "PUC-VBX1-SSI_3.00_and_before",
          "PUC-MBX1-SGI_4.00_and_before",
          "PUC-MBX2-SGI_4.00_and_before",
          "PUC-RBX1-SGI_4.00_and_before",
          "PUC-VBX1-SGI_4.00_and_before"
        ]
      },
      "references": [
        {
          "summary": "CVE-2026-23139",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23139"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "exploitCodeMaturity": "UNPROVEN",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "temporalScore": 6.5
          },
          "products": [
            "PUC-MBX1-SSI_3.00_and_before",
            "PUC-MBX2-SSI_3.00_and_before",
            "PUC-RBX1-SSI_3.00_and_before",
            "PUC-VBX1-SSI_3.00_and_before",
            "PUC-MBX1-SGI_4.00_and_before",
            "PUC-MBX2-SGI_4.00_and_before",
            "PUC-RBX1-SGI_4.00_and_before",
            "PUC-VBX1-SGI_4.00_and_before"
          ]
        }
      ],
      "title": "Linux Kernel Vulnerable to Denial-of-Service (DoS) via Improper Garbage Collection in 'nf_conncount' Component"
    },
    {
      "cve": "CVE-2026-22979",
      "cwe": {
        "id": "CWE-401",
        "name": "Missing Release of Memory after Effective Lifetime"
      },
      "notes": [
        {
          "category": "summary",
          "text": "The Linux kernel is vulnerable to a memory leak due to improper handling of socket memory accounting in the `skb_segment_list` function. This could allow an attacker to cause a denial-of-service (DoS) by preventing socket destruction and leading to persistent memory leaks."
        }
      ],
      "product_status": {
        "fixed": [
          "PUC-MBX1-SSI_3.05",
          "PUC-MBX2-SSI_3.05",
          "PUC-RBX1-SSI_3.05",
          "PUC-VBX1-SSI_3.05",
          "PUC-MBX1-SGI_4.10",
          "PUC-MBX2-SGI_4.10",
          "PUC-RBX1-SGI_4.10",
          "PUC-VBX1-SGI_4.10"
        ],
        "known_affected": [
          "PUC-MBX1-SSI_3.00_and_before",
          "PUC-MBX2-SSI_3.00_and_before",
          "PUC-RBX1-SSI_3.00_and_before",
          "PUC-VBX1-SSI_3.00_and_before",
          "PUC-MBX1-SGI_4.00_and_before",
          "PUC-MBX2-SGI_4.00_and_before",
          "PUC-RBX1-SGI_4.00_and_before",
          "PUC-VBX1-SGI_4.00_and_before"
        ]
      },
      "references": [
        {
          "summary": "CVE-2026-22979",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22979"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "exploitCodeMaturity": "UNPROVEN",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "temporalScore": 5.7
          },
          "products": [
            "PUC-MBX1-SSI_3.00_and_before",
            "PUC-MBX2-SSI_3.00_and_before",
            "PUC-RBX1-SSI_3.00_and_before",
            "PUC-VBX1-SSI_3.00_and_before",
            "PUC-MBX1-SGI_4.00_and_before",
            "PUC-MBX2-SGI_4.00_and_before",
            "PUC-RBX1-SGI_4.00_and_before",
            "PUC-VBX1-SGI_4.00_and_before"
          ]
        }
      ],
      "title": "Linux Kernel Vulnerable to Memory Leak via Improper 'skb_segment_list' Handling in 'net/core/skbuff.c'"
    },
    {
      "cve": "CVE-2026-43452",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "summary",
          "text": "The Linux kernel netfilter framework is vulnerable to improper bounds checking due to insufficient validation in the `xt_tcpudp` and `xt_dccp` option walkers. This could allow an attacker to trigger out-of-bounds reads, potentially leading to denial-of-service (DoS) or other unintended behavior."
        }
      ],
      "product_status": {
        "fixed": [
          "PUC-MBX1-SSI_3.05",
          "PUC-MBX2-SSI_3.05",
          "PUC-RBX1-SSI_3.05",
          "PUC-VBX1-SSI_3.05",
          "PUC-MBX1-SGI_4.10",
          "PUC-MBX2-SGI_4.10",
          "PUC-RBX1-SGI_4.10",
          "PUC-VBX1-SGI_4.10"
        ],
        "known_affected": [
          "PUC-MBX1-SSI_3.00_and_before",
          "PUC-MBX2-SSI_3.00_and_before",
          "PUC-RBX1-SSI_3.00_and_before",
          "PUC-VBX1-SSI_3.00_and_before",
          "PUC-MBX1-SGI_4.00_and_before",
          "PUC-MBX2-SGI_4.00_and_before",
          "PUC-RBX1-SGI_4.00_and_before",
          "PUC-VBX1-SGI_4.00_and_before"
        ]
      },
      "references": [
        {
          "summary": "CVE-2026-43452",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43452"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "exploitCodeMaturity": "UNPROVEN",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "temporalScore": 5.7
          },
          "products": [
            "PUC-MBX1-SSI_3.00_and_before",
            "PUC-MBX2-SSI_3.00_and_before",
            "PUC-RBX1-SSI_3.00_and_before",
            "PUC-VBX1-SSI_3.00_and_before",
            "PUC-MBX1-SGI_4.00_and_before",
            "PUC-MBX2-SGI_4.00_and_before",
            "PUC-RBX1-SGI_4.00_and_before",
            "PUC-VBX1-SGI_4.00_and_before"
          ]
        }
      ],
      "title": "Linux Kernel Vulnerable to Denial-of-Service (DoS) via Out-of-Bounds Read in 'xt_tcpudp.c' and 'xt_dccp.c'"
    },
    {
      "cve": "CVE-2026-21717",
      "cwe": {
        "id": "CWE-407",
        "name": "Inefficient Algorithmic Complexity"
      },
      "notes": [
        {
          "category": "summary",
          "text": "Node.js contains a denial-of-service (DoS) issue due to a hash collision flaw in the V8 Javascript engine, where integer-like strings may be hashed to their numeric value, leading to hash collision. This may be exploited by a remote attacker by passing crafted maliciously crafted content, which when processed by could result in the degradation of underlying application performance."
        }
      ],
      "product_status": {
        "fixed": [
          "PUC-MBX1-SGI_4.10",
          "PUC-MBX2-SGI_4.10",
          "PUC-RBX1-SGI_4.10",
          "PUC-VBX1-SGI_4.10",
          "PUC-MBX1-SSI_3.05",
          "PUC-MBX2-SSI_3.05",
          "PUC-RBX1-SSI_3.05",
          "PUC-VBX1-SSI_3.05"
        ],
        "known_affected": [
          "PUC-MBX1-SSI_3.00_and_before",
          "PUC-MBX2-SSI_3.00_and_before",
          "PUC-RBX1-SSI_3.00_and_before",
          "PUC-VBX1-SSI_3.00_and_before",
          "PUC-MBX1-SGI_4.00_and_before",
          "PUC-MBX2-SGI_4.00_and_before",
          "PUC-RBX1-SGI_4.00_and_before",
          "PUC-VBX1-SGI_4.00_and_before"
        ]
      },
      "references": [
        {
          "summary": "CVE-2026-21717",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-21717"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "integrityImpact": "NONE",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "exploitCodeMaturity": "UNPROVEN",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "temporalScore": 4.6
          },
          "products": [
            "PUC-MBX1-SSI_3.00_and_before",
            "PUC-MBX2-SSI_3.00_and_before",
            "PUC-RBX1-SSI_3.00_and_before",
            "PUC-VBX1-SSI_3.00_and_before",
            "PUC-MBX1-SGI_4.00_and_before",
            "PUC-MBX2-SGI_4.00_and_before",
            "PUC-RBX1-SGI_4.00_and_before",
            "PUC-VBX1-SGI_4.00_and_before"
          ]
        }
      ],
      "title": "node.js Vulnerable to Denial-of-Service (DoS) via Hash Table Collision in V8 Component"
    },
    {
      "cve": "CVE-2026-21714",
      "cwe": {
        "id": "CWE-401",
        "name": "Missing Release of Memory after Effective Lifetime"
      },
      "notes": [
        {
          "category": "summary",
          "text": "Node.js is vulnerable to denial-of-service (DoS) due to improper handling of the `NGHTTP2_ERR_FLOW_CONTROL` error in the `Http2Session` component. This could allow an attacker to exploit a connection-level `WINDOW_UPDATE` frame that causes the flow control window to exceed its maximum limit, leading to a memory leak and eventual resource exhaustion."
        }
      ],
      "product_status": {
        "fixed": [
          "PUC-MBX1-SSI_3.05",
          "PUC-MBX2-SSI_3.05",
          "PUC-RBX1-SSI_3.05",
          "PUC-VBX1-SSI_3.05",
          "PUC-MBX1-SGI_4.10",
          "PUC-MBX2-SGI_4.10",
          "PUC-RBX1-SGI_4.10",
          "PUC-VBX1-SGI_4.10"
        ],
        "known_affected": [
          "PUC-MBX1-SSI_3.00_and_before",
          "PUC-MBX2-SSI_3.00_and_before",
          "PUC-RBX1-SSI_3.00_and_before",
          "PUC-VBX1-SSI_3.00_and_before",
          "PUC-MBX1-SGI_4.00_and_before",
          "PUC-MBX2-SGI_4.00_and_before",
          "PUC-RBX1-SGI_4.00_and_before",
          "PUC-VBX1-SGI_4.00_and_before"
        ]
      },
      "references": [
        {
          "summary": "CVE-2026-21714",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-21714"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "exploitCodeMaturity": "UNPROVEN",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "temporalScore": 6.5
          },
          "products": [
            "PUC-MBX1-SSI_3.00_and_before",
            "PUC-MBX2-SSI_3.00_and_before",
            "PUC-RBX1-SSI_3.00_and_before",
            "PUC-VBX1-SSI_3.00_and_before",
            "PUC-MBX1-SGI_4.00_and_before",
            "PUC-MBX2-SGI_4.00_and_before",
            "PUC-RBX1-SGI_4.00_and_before",
            "PUC-VBX1-SGI_4.00_and_before"
          ]
        }
      ],
      "title": "Node.js Vulnerable to Denial-of-Service (DoS) via Flow Control Error in 'Http2Session' Component"
    }
  ]
}