{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "nl",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions:\n\n    NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein.\n\n    NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory.\n    This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            },
            {
                "category": "description",
                "text": "Microsoft heeft kwetsbaarheden verholpen in diverse Developer Tools.",
                "title": "Feiten"
            },
            {
                "category": "description",
                "text": "Een kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service te veroorzaken, zichzelf verhoogde rechten toe te kennen of willekeurige code uit te voeren met rechten van het slachtoffer.\n\nVoor succesvol misbruik moet de kwaadwillende het slachtoffer misleiden een malafide bestand te openen en uit te voeren.\n\n```\n.NET, .NET Framework, Visual Studio: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43483 | 7.50 | Denial-of-Service                   | \n| CVE-2024-43484 | 7.50 | Denial-of-Service                   | \n|----------------|------|-------------------------------------|\n\nVisual Studio Code: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43601 | 7.10 | Uitvoeren van willekeurige code     | \n| CVE-2024-43488 | 8.80 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\n.NET and Visual Studio: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-38229 | 8.10 | Uitvoeren van willekeurige code     | \n| CVE-2024-43485 | 7.50 | Denial-of-Service                   | \n|----------------|------|-------------------------------------|\n\nDeepSpeed: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43497 | 8.40 | Uitvoeren van willekeurige code     | \n|----------------|------|-------------------------------------|\n\nVisual Studio: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43603 | 5.50 | Denial-of-Service                   | \n|----------------|------|-------------------------------------|\n\nVisual C++ Redistributable Installer: \n|----------------|------|-------------------------------------|\n| CVE-ID         | CVSS | Impact                              |\n|----------------|------|-------------------------------------|\n| CVE-2024-43590 | 7.80 | Verkrijgen van verhoogde rechten    | \n|----------------|------|-------------------------------------|\n```",
                "title": "Interpretaties"
            },
            {
                "category": "description",
                "text": "Microsoft heeft updates beschikbaar gesteld waarmee de beschreven kwetsbaarheden worden verholpen. We raden u aan om deze updates te installeren. Meer informatie over de kwetsbaarheden, de installatie van de updates en eventuele work-arounds vindt u op:\n\nhttps://portal.msrc.microsoft.com/en-us/security-guidance",
                "title": "Oplossingen"
            },
            {
                "category": "general",
                "text": "medium",
                "title": "Kans"
            },
            {
                "category": "general",
                "text": "high",
                "title": "Schade"
            },
            {
                "category": "general",
                "text": "Improper Link Resolution Before File Access ('Link Following')",
                "title": "CWE-59"
            },
            {
                "category": "general",
                "text": "Inefficient Algorithmic Complexity",
                "title": "CWE-407"
            },
            {
                "category": "general",
                "text": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
                "title": "CWE-77"
            },
            {
                "category": "general",
                "text": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
                "title": "CWE-362"
            },
            {
                "category": "general",
                "text": "Missing Authentication for Critical Function",
                "title": "CWE-306"
            },
            {
                "category": "general",
                "text": "Improper Access Control",
                "title": "CWE-284"
            },
            {
                "category": "general",
                "text": "Use After Free",
                "title": "CWE-416"
            },
            {
                "category": "general",
                "text": "Memory Allocation with Excessive Size Value",
                "title": "CWE-789"
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "Nationaal Cyber Security Centrum",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "Kwetsbaarheden verholpen in Microsoft Developer Tools",
        "tracking": {
            "current_release_date": "2024-10-08T19:59:28.385237Z",
            "id": "NCSC-2024-0395",
            "initial_release_date": "2024-10-08T19:59:28.385237Z",
            "revision_history": [
                {
                    "date": "2024-10-08T19:59:28.385237Z",
                    "number": "0",
                    "summary": "Initiele versie"
                }
            ],
            "status": "final",
            "version": "1.0.0"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "category": "product_name",
                        "name": ".net_6.0",
                        "product": {
                            "name": ".net_6.0",
                            "product_id": "CSAFPID-1455597",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:.net_6.0:6.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": ".net_8.0",
                        "product": {
                            "name": ".net_8.0",
                            "product_id": "CSAFPID-1667134",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:.net_8.0:8.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "deepspeed",
                        "product": {
                            "name": "deepspeed",
                            "product_id": "CSAFPID-1667142",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:deepspeed:0.1.1:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_.net_framework_2.0_service_pack_2",
                        "product": {
                            "name": "microsoft_.net_framework_2.0_service_pack_2",
                            "product_id": "CSAFPID-1453794",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_.net_framework_2.0_service_pack_2:2.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_.net_framework_3.0_service_pack_2",
                        "product": {
                            "name": "microsoft_.net_framework_3.0_service_pack_2",
                            "product_id": "CSAFPID-1453795",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_.net_framework_3.0_service_pack_2:3.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_.net_framework_3.5.1",
                        "product": {
                            "name": "microsoft_.net_framework_3.5.1",
                            "product_id": "CSAFPID-1453797",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_.net_framework_3.5.1:3.5.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_.net_framework_3.5",
                        "product": {
                            "name": "microsoft_.net_framework_3.5",
                            "product_id": "CSAFPID-1453796",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_.net_framework_3.5:3.5.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_.net_framework_3.5_and_4.7.2",
                        "product": {
                            "name": "microsoft_.net_framework_3.5_and_4.7.2",
                            "product_id": "CSAFPID-1453789",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_.net_framework_3.5_and_4.7.2:4.7.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_.net_framework_3.5_and_4.8.1",
                        "product": {
                            "name": "microsoft_.net_framework_3.5_and_4.8.1",
                            "product_id": "CSAFPID-1453786",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_.net_framework_3.5_and_4.8.1:4.8.1:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_.net_framework_3.5_and_4.8",
                        "product": {
                            "name": "microsoft_.net_framework_3.5_and_4.8",
                            "product_id": "CSAFPID-1453788",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_.net_framework_3.5_and_4.8:4.8.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_.net_framework_4.6.2",
                        "product": {
                            "name": "microsoft_.net_framework_4.6.2",
                            "product_id": "CSAFPID-1453792",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_.net_framework_4.6.2:4.7.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_.net_framework_4.6.2_4.7_4.7.1_4.7.2",
                        "product": {
                            "name": "microsoft_.net_framework_4.6.2_4.7_4.7.1_4.7.2",
                            "product_id": "CSAFPID-1453791",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_.net_framework_4.6.2_4.7_4.7.1_4.7.2:4.7.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_.net_framework_4.6_4.6.2",
                        "product": {
                            "name": "microsoft_.net_framework_4.6_4.6.2",
                            "product_id": "CSAFPID-1455895",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_.net_framework_4.6_4.6.2:10.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_.net_framework_4.8",
                        "product": {
                            "name": "microsoft_.net_framework_4.8",
                            "product_id": "CSAFPID-1453787",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_.net_framework_4.8:4.8.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_visual_studio_2015_update_3",
                        "product": {
                            "name": "microsoft_visual_studio_2015_update_3",
                            "product_id": "CSAFPID-1455709",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_visual_studio_2015_update_3:14.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_visual_studio_2017_version_15.9__includes_15.0_-_15.8_",
                        "product": {
                            "name": "microsoft_visual_studio_2017_version_15.9__includes_15.0_-_15.8_",
                            "product_id": "CSAFPID-1455690",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_visual_studio_2017_version_15.9__includes_15.0_-_15.8_:15.9.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_visual_studio_2019_version_16.11__includes_16.0_-_16.10_",
                        "product": {
                            "name": "microsoft_visual_studio_2019_version_16.11__includes_16.0_-_16.10_",
                            "product_id": "CSAFPID-1455612",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_visual_studio_2019_version_16.11__includes_16.0_-_16.10_:16.11.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_visual_studio_2022_version_17.10",
                        "product": {
                            "name": "microsoft_visual_studio_2022_version_17.10",
                            "product_id": "CSAFPID-1477293",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_visual_studio_2022_version_17.10:17.10:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_visual_studio_2022_version_17.11",
                        "product": {
                            "name": "microsoft_visual_studio_2022_version_17.11",
                            "product_id": "CSAFPID-1638303",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_visual_studio_2022_version_17.11:17.11:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_visual_studio_2022_version_17.6",
                        "product": {
                            "name": "microsoft_visual_studio_2022_version_17.6",
                            "product_id": "CSAFPID-1454046",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_visual_studio_2022_version_17.6:17.6.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "microsoft_visual_studio_2022_version_17.8",
                        "product": {
                            "name": "microsoft_visual_studio_2022_version_17.8",
                            "product_id": "CSAFPID-1454047",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:microsoft_visual_studio_2022_version_17.8:17.8.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "visual_c___redistributable_installer",
                        "product": {
                            "name": "visual_c___redistributable_installer",
                            "product_id": "CSAFPID-1667144",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:visual_c___redistributable_installer:10.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "visual_studio_code",
                        "product": {
                            "name": "visual_studio_code",
                            "product_id": "CSAFPID-138831",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:visual_studio_code:1.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "visual_studio_code",
                        "product": {
                            "name": "visual_studio_code",
                            "product_id": "CSAFPID-1667130",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:microsoft:visual_studio_code:n_a:*:*:*:*:*:*:*"
                            }
                        }
                    }
                ],
                "category": "vendor",
                "name": "microsoft"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2024-38229",
            "cwe": {
                "id": "CWE-416",
                "name": "Use After Free"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Use After Free",
                    "title": "CWE-416"
                },
                {
                    "category": "other",
                    "text": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
                    "title": "CWE-362"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1454046",
                    "CSAFPID-1454047",
                    "CSAFPID-1477293",
                    "CSAFPID-1667134",
                    "CSAFPID-1638303"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-38229",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-38229.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1454046",
                        "CSAFPID-1454047",
                        "CSAFPID-1477293",
                        "CSAFPID-1667134",
                        "CSAFPID-1638303"
                    ]
                }
            ],
            "title": "CVE-2024-38229"
        },
        {
            "cve": "CVE-2024-43483",
            "cwe": {
                "id": "CWE-407",
                "name": "Inefficient Algorithmic Complexity"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Inefficient Algorithmic Complexity",
                    "title": "CWE-407"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1454046",
                    "CSAFPID-1454047",
                    "CSAFPID-1477293",
                    "CSAFPID-1638303",
                    "CSAFPID-1667134",
                    "CSAFPID-1455597",
                    "CSAFPID-1453787",
                    "CSAFPID-1453788",
                    "CSAFPID-1453789",
                    "CSAFPID-1453791",
                    "CSAFPID-1453786",
                    "CSAFPID-1453792",
                    "CSAFPID-1455895",
                    "CSAFPID-1453794",
                    "CSAFPID-1453795",
                    "CSAFPID-1453796",
                    "CSAFPID-1453797"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43483",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43483.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1454046",
                        "CSAFPID-1454047",
                        "CSAFPID-1477293",
                        "CSAFPID-1638303",
                        "CSAFPID-1667134",
                        "CSAFPID-1455597",
                        "CSAFPID-1453787",
                        "CSAFPID-1453788",
                        "CSAFPID-1453789",
                        "CSAFPID-1453791",
                        "CSAFPID-1453786",
                        "CSAFPID-1453792",
                        "CSAFPID-1455895",
                        "CSAFPID-1453794",
                        "CSAFPID-1453795",
                        "CSAFPID-1453796",
                        "CSAFPID-1453797"
                    ]
                }
            ],
            "title": "CVE-2024-43483"
        },
        {
            "cve": "CVE-2024-43484",
            "cwe": {
                "id": "CWE-407",
                "name": "Inefficient Algorithmic Complexity"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Inefficient Algorithmic Complexity",
                    "title": "CWE-407"
                },
                {
                    "category": "other",
                    "text": "Memory Allocation with Excessive Size Value",
                    "title": "CWE-789"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1454046",
                    "CSAFPID-1454047",
                    "CSAFPID-1477293",
                    "CSAFPID-1638303",
                    "CSAFPID-1455597",
                    "CSAFPID-1667134",
                    "CSAFPID-1453789",
                    "CSAFPID-1453788",
                    "CSAFPID-1453791",
                    "CSAFPID-1453786",
                    "CSAFPID-1453792",
                    "CSAFPID-1455895",
                    "CSAFPID-1453794",
                    "CSAFPID-1453795",
                    "CSAFPID-1453796",
                    "CSAFPID-1453797",
                    "CSAFPID-1453787"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43484",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43484.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1454046",
                        "CSAFPID-1454047",
                        "CSAFPID-1477293",
                        "CSAFPID-1638303",
                        "CSAFPID-1455597",
                        "CSAFPID-1667134",
                        "CSAFPID-1453789",
                        "CSAFPID-1453788",
                        "CSAFPID-1453791",
                        "CSAFPID-1453786",
                        "CSAFPID-1453792",
                        "CSAFPID-1455895",
                        "CSAFPID-1453794",
                        "CSAFPID-1453795",
                        "CSAFPID-1453796",
                        "CSAFPID-1453797",
                        "CSAFPID-1453787"
                    ]
                }
            ],
            "title": "CVE-2024-43484"
        },
        {
            "cve": "CVE-2024-43485",
            "cwe": {
                "id": "CWE-407",
                "name": "Inefficient Algorithmic Complexity"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Inefficient Algorithmic Complexity",
                    "title": "CWE-407"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1454046",
                    "CSAFPID-1454047",
                    "CSAFPID-1477293",
                    "CSAFPID-1638303",
                    "CSAFPID-1667134",
                    "CSAFPID-1455597"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43485",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43485.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1454046",
                        "CSAFPID-1454047",
                        "CSAFPID-1477293",
                        "CSAFPID-1638303",
                        "CSAFPID-1667134",
                        "CSAFPID-1455597"
                    ]
                }
            ],
            "title": "CVE-2024-43485"
        },
        {
            "cve": "CVE-2024-43590",
            "cwe": {
                "id": "CWE-284",
                "name": "Improper Access Control"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Access Control",
                    "title": "CWE-284"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1667144",
                    "CSAFPID-1455690",
                    "CSAFPID-1455612",
                    "CSAFPID-1454046",
                    "CSAFPID-1454047",
                    "CSAFPID-1477293",
                    "CSAFPID-1638303"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43590",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43590.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1667144",
                        "CSAFPID-1455690",
                        "CSAFPID-1455612",
                        "CSAFPID-1454046",
                        "CSAFPID-1454047",
                        "CSAFPID-1477293",
                        "CSAFPID-1638303"
                    ]
                }
            ],
            "title": "CVE-2024-43590"
        },
        {
            "cve": "CVE-2024-43603",
            "cwe": {
                "id": "CWE-59",
                "name": "Improper Link Resolution Before File Access ('Link Following')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Link Resolution Before File Access ('Link Following')",
                    "title": "CWE-59"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1638303",
                    "CSAFPID-1455690",
                    "CSAFPID-1455612",
                    "CSAFPID-1454046",
                    "CSAFPID-1454047",
                    "CSAFPID-1477293",
                    "CSAFPID-1455709"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43603",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43603.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C",
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1638303",
                        "CSAFPID-1455690",
                        "CSAFPID-1455612",
                        "CSAFPID-1454046",
                        "CSAFPID-1454047",
                        "CSAFPID-1477293",
                        "CSAFPID-1455709"
                    ]
                }
            ],
            "title": "CVE-2024-43603"
        },
        {
            "cve": "CVE-2024-43601",
            "cwe": {
                "id": "CWE-77",
                "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
                    "title": "CWE-77"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-138831"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43601",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43601.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-138831"
                    ]
                }
            ],
            "title": "CVE-2024-43601"
        },
        {
            "cve": "CVE-2024-43488",
            "cwe": {
                "id": "CWE-306",
                "name": "Missing Authentication for Critical Function"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Missing Authentication for Critical Function",
                    "title": "CWE-306"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1667130"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43488",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43488.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1667130"
                    ]
                }
            ],
            "title": "CVE-2024-43488"
        },
        {
            "cve": "CVE-2024-43497",
            "cwe": {
                "id": "CWE-77",
                "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
                    "title": "CWE-77"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1667142"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-43497",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-43497.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1667142"
                    ]
                }
            ],
            "title": "CVE-2024-43497"
        }
    ]
}