<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Utimaco Portal</title>
  <link rel="self" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636" />
  <subtitle>Utimaco Portal</subtitle>
  <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636</id>
  <updated>2026-05-25T22:15:22Z</updated>
  <dc:date>2026-05-25T22:15:22Z</dc:date>
  <entry>
    <title>CVE-2025-15467 – AEAD Cipher, OpenSSL</title>
    <link rel="alternate" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=2352050" />
    <author>
      <name>Julian Koeberlin</name>
    </author>
    <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=2352050</id>
    <updated>2026-03-11T21:18:23Z</updated>
    <published>2026-03-11T19:48:00Z</published>
    <summary type="html">&lt;p&gt;Utimaco has analyzed its product portfolio for impact from &lt;a
    href="https://nvd.nist.gov/vuln/detail/CVE-2025-15467"&gt;CVE
  2025-15467&lt;/a&gt;. Products that have been investigated and have reached
  a conclusion of &amp;quot;Impacted&amp;quot; are listed in &lt;a
    href="https://support.hsm.utimaco.com/documents/d/20182/eskm-v8-cve-bulletin-2025_15467"&gt;this
  bulletin&lt;/a&gt;.&lt;br&gt; ​​​​​&lt;br&gt; ​​​​​​​If you have questions, please
  contact Utimaco Support.&lt;/p&gt;
    &lt;p&gt;The latest updates are published here: &lt;a href="https://www.utimaco.com/support"&gt;https://www.utimaco.com/support&lt;/a&gt;&lt;/p&gt;</summary>
    <dc:creator>Julian Koeberlin</dc:creator>
    <dc:date>2026-03-11T19:48:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2024-6387 - SSHZeroDay</title>
    <link rel="alternate" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=1817689" />
    <author>
      <name>René Kocgazi</name>
    </author>
    <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=1817689</id>
    <updated>2024-08-13T15:35:51Z</updated>
    <published>2024-07-29T11:33:00Z</published>
    <summary type="html">&lt;p&gt;Utimaco has analysed its product portfolio for impact from &lt;a
  href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6387"&gt;CVE-2024-6387&lt;/a&gt;.
  Products that have been investigated and have reached a conclusion of
  &amp;quot;Impacted&amp;quot; are listed in &lt;a
    href="https://support.hsm.utimaco.com/documents/d/20182/security-advisory-cve-2024-6387-sshzeroday"&gt;this
  bulletin&lt;/a&gt;.&lt;br&gt; ​​​​​​​If you have questions, please contact Utimaco Support.&lt;/p&gt;
     &lt;p&gt;The latest updates are published here: &lt;a href="https://www.utimaco.com/support"&gt;https://www.utimaco.com/support&lt;/a&gt;&lt;/p&gt;</summary>
    <dc:creator>René Kocgazi</dc:creator>
    <dc:date>2024-07-29T11:33:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2021-44228/45046 - Log4J vulnerability</title>
    <link rel="alternate" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=1148908" />
    <author>
      <name>René Kocgazi</name>
    </author>
    <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=1148908</id>
    <updated>2022-01-27T18:12:07Z</updated>
    <published>2022-01-27T13:36:00Z</published>
    <summary type="html">&lt;p&gt;Utimaco has analysed its product portfolio for impact from &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228"&gt;CVE-2021-44228&lt;/a&gt; and &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046"&gt;CVE-2021-45046&lt;/a&gt;. Products that have been investigated and have reached a conclusion of "Impacted" are listed in this bulletin, along with mitigation steps. Any products not listed in &lt;a href="https://support.hsm.utimaco.com/documents/20182/39856/Utimaco+Security+Bulletin-v36-20220127_174923.pdf/d7e0ca96-99a6-453e-86a5-955bab3a5a77"&gt;this bulletin&lt;/a&gt; are evaluated as "Not Affected" at the time of publication. If you have questions, please contact Utimaco Support.&lt;/p&gt;

&lt;p&gt;The latest updates are published here: &lt;a href="https://www.utimaco.com/support"&gt;https://www.utimaco.com/support&lt;/a&gt;&lt;/p&gt;</summary>
    <dc:creator>René Kocgazi</dc:creator>
    <dc:date>2022-01-27T13:36:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2020-26155 Windows Privilege Escalation</title>
    <link rel="alternate" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=927185" />
    <author>
      <name>Marcel Hammes</name>
    </author>
    <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=927185</id>
    <updated>2021-04-12T07:54:51Z</updated>
    <published>2021-03-29T16:30:00Z</published>
    <summary type="html">&lt;p&gt;UTIMACO has been made aware of a vulnerability affecting the Windows installations of several product packages. When installing product packages of the Affected Products, using the Windows installer shipped on the product CD, incorrect folder permissions are configured. Also, the PIN Pad Daemon “PPD” is configured to run under LocalSystem account. Both could allow for an attacker to escalate Windows privileges from a standard “Authenticated User” to that of an Administrator or SYSTEM. Please consult &lt;a href="https://support.hsm.utimaco.com/documents/20182/810270/UTIMACO_Security_Advisory_Windows_Permissions_20210325.pdf/f58cad8f-4c48-454b-bf8a-bd8b3eb7dfb5"&gt;CVE-2020-26155 Security Advisory&lt;/a&gt; to find out how to prevent possible security threats effectively.&lt;br /&gt;
Thanks to Richard Davy from ECSC (www.ecsc.co.uk) for the responsible disclosure and his valuable input for mitigation of this vulnerability.&lt;/p&gt;</summary>
    <dc:creator>Marcel Hammes</dc:creator>
    <dc:date>2021-03-29T16:30:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2018-19589 - PKCS#11 Security Officer Rights</title>
    <link rel="alternate" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=324968" />
    <author>
      <name>Florian Sehl</name>
    </author>
    <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=324968</id>
    <updated>2019-03-13T12:16:20Z</updated>
    <published>2019-03-13T00:00:00Z</published>
    <summary type="html">&lt;p&gt;Utimaco has been informed about a vulnerability affecting Utimaco’s product package “SecurityServer”: a PKCS#11 Security Officer of a specific PKCS#11 slot is able to read attributes of keys in a different slot, and delete keys in a different slot, if such keys are stored in external key storage outside the HSM. This vulnerability has been filed under ID &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19589"&gt;CVE-2018-19589&lt;/a&gt; in the “Common Vulnerabilities and Exposures” list. Please consult &lt;a href="https://support.hsm.utimaco.com/documents/20182/39856/CS_AF_CVE-2018-19589_P11_SO_Rights.pdf/daba272a-a103-436f-b09b-b8fc38ff8489" style="display: inline !important;"&gt;&lt;i class="icon fa-file-pdf-o"&gt;&amp;nbsp;&lt;/i&gt;CVE-2018-19589 Security Advisory&lt;/a&gt; for more information.&lt;/p&gt;</summary>
    <dc:creator>Florian Sehl</dc:creator>
    <dc:date>2019-03-13T00:00:00Z</dc:date>
  </entry>
  <entry>
    <title>Meltdown and Spectre Vulnerabilities (CVE-2017-5754, CVE-2017-5753, and CVE-2017-5715)</title>
    <link rel="alternate" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=187701" />
    <author>
      <name>Florian Sehl</name>
    </author>
    <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=187701</id>
    <updated>2018-01-05T14:34:08Z</updated>
    <published>2018-01-05T13:46:00Z</published>
    <summary type="html">Utimaco declares that CryptoServer Hardware Security Modules (HSMs) including their firmware are not affected by these vulnerabilities. Please consult &lt;a href="https://support.hsm.utimaco.com/documents/20182/39856/CVE-2017-5754-Meldown-Spectre/280c53f8-e51f-4a29-85a7-77a56abd026f" style="display: inline !important;"&gt;&lt;i class="icon fa-file-pdf-o"&gt;&amp;nbsp;&lt;/i&gt;CVE-2017-5754 Security Advisory&lt;/a&gt; for more information.</summary>
    <dc:creator>Florian Sehl</dc:creator>
    <dc:date>2018-01-05T13:46:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2017-15361 - ROCA Vulnerable RSA generation</title>
    <link rel="alternate" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=166635" />
    <author>
      <name>Frank Thunig</name>
    </author>
    <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=166635</id>
    <updated>2017-10-17T11:21:49Z</updated>
    <published>2017-10-17T09:21:00Z</published>
    <summary type="html">&lt;p&gt;Utimaco has been made aware of the vulnerability CVE-2017-15361 aka. ROCA (The Return of Coppersmith's Attack), affecting the RSA library in Infineon chips. Utimaco declares that CryptoServer Hardware Security Modules (HSM) including their firmware and tools are not affected by this vulnerability. Please consult &lt;a href="https://support.hsm.utimaco.com/documents/20182/39856/CVE-2017-15361+ROCA.pdf/3a711070-65c4-495d-b4a1-7d90aeab6efd"&gt;CVE-2017-15361&lt;/a&gt; for details.&lt;/p&gt;</summary>
    <dc:creator>Frank Thunig</dc:creator>
    <dc:date>2017-10-17T09:21:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2015-6924 - Elliptic Curve key disclosure</title>
    <link rel="alternate" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=39877" />
    <author>
      <name>Dieter Bong</name>
    </author>
    <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=39877</id>
    <updated>2015-10-08T12:09:09Z</updated>
    <published>2015-10-05T12:47:00Z</published>
    <summary type="html">&lt;p&gt;Utimaco has been informed about a vulnerability affecting Utimaco’s product package “SecurityServer”. It allows an authenticated user to disclose a secret Elliptic Curve (EC) key stored inside an Utimaco HSM. This vulnerability has been filed under ID &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6924"&gt;CVE-2015-6924&lt;/a&gt; in the “Common Vulnerabilities and Exposures” list. Please consult our &lt;a href="https://support.hsm.utimaco.com/documents/20182/39856/CVE-2015-6924+Security+Advisory/01105136-1b57-4b05-b988-3121530d39c3"&gt;&lt;i class="icon fa-file-pdf-o"&gt;&amp;nbsp;&lt;/i&gt;CVE-2015-6924 Security Advisory&lt;/a&gt; for information about the vulnerability and how to fix it.&lt;/p&gt;</summary>
    <dc:creator>Dieter Bong</dc:creator>
    <dc:date>2015-10-05T12:47:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2015-5464 - Key extraction vulnerability</title>
    <link rel="alternate" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=39685" />
    <author>
      <name>Eric Barmeyer</name>
    </author>
    <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=39685</id>
    <updated>2015-10-05T08:35:04Z</updated>
    <published>2015-09-22T11:11:00Z</published>
    <summary type="html">&lt;p&gt;Utimaco has been made aware of the so-called key extraction vulnerability &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5464"&gt;CVE-2015-5464&lt;/a&gt;. The vulnerability &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5464"&gt;CVE-2015-5464&lt;/a&gt; is entirely based on functions and mechanisms specified in the PKCS#11 standard, in particular the &lt;code&gt;C_Derive&lt;/code&gt; function with mechanism &lt;code&gt;CKM_EXTRACT_KEY_FROM_KEY&lt;/code&gt;. Hence, all standard-compliant PKCS#11 implementations supporting these mechanisms are affected. Whether a given application is actually subject to this vulnerability depends on the specific environment and setting of key usage flags. We strongly encourage our customers to implement measures and follow guidelines as described in &lt;a href="https://support.hsm.utimaco.com/documents/20182/39856/Utimaco+Company+Statement+concerning+key+extraction+vulnerability.pdf/8efa1ea9-4e6d-4202-b294-323ba259fbe7"&gt;&lt;i class="icon fa-file-pdf-o"&gt;&amp;nbsp;&lt;/i&gt;Utimaco Company Statement concerning key extraction vulnerability&lt;/a&gt;.&lt;/p&gt;</summary>
    <dc:creator>Eric Barmeyer</dc:creator>
    <dc:date>2015-09-22T11:11:00Z</dc:date>
  </entry>
  <entry>
    <title>Leap Second</title>
    <link rel="alternate" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=39677" />
    <author>
      <name>Eric Barmeyer</name>
    </author>
    <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=39677</id>
    <updated>2015-09-30T11:12:52Z</updated>
    <published>2015-05-27T11:10:00Z</published>
    <summary type="html">The imminent insertion of a leap second on June 30, 2015 has raised concerns about availability and reliability of computer systems. Utimaco has conducted an analysis of possible impacts of this leap second on our products. This analysis has led to the conclusion that handling of the leap second by CryptoServer HSMs and CryptoServer LAN appliances ensures valid system time settings. Neither degradation of service nor operational failure nor any security-relevant issues are to be expected.</summary>
    <dc:creator>Eric Barmeyer</dc:creator>
    <dc:date>2015-05-27T11:10:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2015-0235 aka "GHOST"</title>
    <link rel="alternate" href="https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=39667" />
    <author>
      <name>Eric Barmeyer</name>
    </author>
    <id>https://support.hsm.utimaco.com/c/blogs/find_entry?p_l_id=39636&amp;entryId=39667</id>
    <updated>2015-09-30T11:14:30Z</updated>
    <published>2015-02-03T09:52:00Z</published>
    <summary type="html">Utimaco has become aware of vulnerability &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0235"&gt;CVE-2015-0235&lt;/a&gt; aka "GHOST" affecting “gethostbyname” functions of Linux library glibc. Analysis of the impact of GHOST on Utimaco HSM products has led to the following conclusions:

&lt;ul&gt;
	&lt;li&gt;Utimaco’s “CryptoServer LAN” appliances embed a vulnerable version of glibc. The GHOST vulnerability cannot be exploited due to the intentionally limited functionality of the CryptoServer LAN hardened Operating System and further mitigating factors.&lt;/li&gt;
	&lt;li&gt;Furthermore, some tools and libraries delivered with Utimaco’s HSM product packages call the affected gethostbyname() function. These software modules load glibc dynamically at runtime. Although keys stored inside the HSM cannot be retrieved by an attacker, he might gain access to other data if the host computer relies on an affected version of glibc. We therefore strongly recommend upgrading host systems to glibc version 2.18 or above.&lt;/li&gt;
&lt;/ul&gt;</summary>
    <dc:creator>Eric Barmeyer</dc:creator>
    <dc:date>2015-02-03T09:52:00Z</dc:date>
  </entry>
</feed>
