ISO/SAE 21434 · Vulnerability management
Vulnerabilities
Tracked CVEs affecting the engineering tool chain, with CVSS rating, mitigation plan and responsible owner.
SeverityStatus
CVE-2025-11832 | Critical | Vector CANoe | 18 SP2 | Vector Informatik | 9.8 | Open | Upgrade to 8.1.5; interim compiler flag workaround | S. Nakamura | 2026-01-03 | |
CVE-2025-10774 | High | Polyspace Bug Finder | R2025a | MathWorks | 8.1 | In Progress | Vendor patch scheduled Q3 | L. Rossi | 2026-02-04 | |
CVE-2026-02219 | Medium | GCC ARM Embedded | 13.2.rel1 | ARM / GNU | 6.4 | Open | Restrict network exposure of build agent | A. Kumar | 2026-03-05 | |
CVE-2025-49021 | High | Medini Analyze | 2025 R1 | ANSYS | 7.5 | Mitigated | Runner isolated in dedicated VLAN | C. Dubois | 2026-04-06 | |
CVE-2026-00918 | Low | Polarion ALM | 24 R2 | Siemens | 3.2 | Closed | Not exploitable in our configuration | S. Nakamura | 2026-05-07 | |
CVE-2025-38447 | Critical | Jenkins | 2.462 LTS | CloudBees | 9.1 | In Progress | Emergency upgrade in validation | L. Rossi | 2026-06-08 | |
CVE-2026-01455 | Medium | GitLab Ultimate | 17.4 | GitLab Inc. | 5.9 | Open | Disable legacy plugin | A. Kumar | 2026-07-09 | |
CVE-2025-27310 | High | Parasoft C/C++test | 2025.1 | Parasoft | 8.6 | Mitigated | WAF rule + credential rotation | C. Dubois | 2026-08-10 | |
CVE-2026-03102 | Low | Enterprise Architect | 17.0 | Sparx Systems | 2.8 | Closed | Fixed in current release | S. Nakamura | 2026-01-11 | |
CVE-2025-44120 | Medium | Black Duck | 2025.4 | Synopsys | 6.8 | Open | Awaiting supplier statement | L. Rossi | 2026-02-12 | |
CVE-2026-04477 | Critical | Coverity | 2025.3 | Synopsys | 9.4 | Open | Tool quarantined until patched | A. Kumar | 2026-03-13 | |
CVE-2025-51009 | High | Jira Software | Cloud | Atlassian | 7.9 | In Progress | Patch under regression test | C. Dubois | 2026-04-14 |
1–12 of 12
Page 1 / 1