SISCO Security
SISCO is committed to providing secure, robust, and cost-effective products. This web page provides our customers and their users with information about known security vulnerabilities that may exist in SISCO’s products.
If you believe you are aware of any potential vulnerability in SISCO's products, please email [email protected]
What is a Security Issue or Vulnerability?
While there might be some disagreement among reasonable people as to the difference between a security vulnerability and a “normal” software bug, SISCO is interested in receiving reports of bugs and vulnerabilities regardless of how you classify them. ANY conditions that cause SISCO’s software products to behave abnormally in a manner that might disrupt data exchange or affect the integrity of the data being exchanged should be treated very seriously and reported to SISCO immediately via the procedure described above.
Existing Security Advisories
SISCO has not had any recent reported issues. Below are publicly known vulnerabilities in SISCO software, including the date of the last known status update. Links are provided below for public disclosures, if known. Please inquire about other issues per the procedures described above. SISCO routinely documents all changes we make to our products in the release notes and provides this information to anyone purchasing our products or receiving an update. Some of these changes may be bug-related while others result from customer suggestions and product improvements. While we try to be explicit in our descriptions, some of those changes may not be identified explicitly as security vulnerabilities. If you have a question about a known security vulnerability, please include that information in your inquiry. SISCO does not publicly disclose security vulnerabilities without first attempting to notify customers and users prior to public disclosure and providing them reasonable time to apply updates. If you are unsure whether a notice applies to your system, please contact SISCO as described above, and we will do our best to provide the information you need to determine how any of these issues will affect your systems.
- Portcullis Vulnerability CVE-2015-6574 affecting some versions of MMS-EASE and AX-S4 ICCP – 26 April 2016
- Heartbleed Impact on SISCO Products – 15 April 2014
- Vulnerability in Windows Common Controls (MS12-060) describes a vulnerability in Microsoft Common Controls used by SISCO’s software that may not get updated during the Windows Update Process. UPDATED: 21 April 2016
- US Cert Vulnerability 145825 regarding SISCO OSI stack used in MMS-EASE, ICCP Toolkit for MMS-EASE, AX-S4 ICCP, and AX-S4 MMS – 17 January 2007
- NESSUS Security Issue – 25 February 2005