Insyde's Security Pledge

Recent Security Advisories

INSYDE-SA-2024017

Product

CVSS Score

Original Date

Last Revised

Supervyse

3.7-5.3

2025-02-11

Summary

Upgrade curl to 8.11.1

Vulnerability Details

CVSS Vector: See in Desc.

Upgrade curl to 8.11.1 for addressing following vulnerabilities.

1. CVE-2024-9681
CVSS: 5.3
Description: HSTS subdomain overwrites parent cache entry

2. CVE-2024-11053
CVSS: 3.7
Description: Netrc and redirect credential leak

Solution Information

OPF 1.0: RV24.06 and after.
OPF 2.0: RV24.12 and after.

Acknowledgements

Revision History

Revision #

Date

Description

1

2025-02-11

Initial Release