
Security advice
We do our best to make you aware of potential security risks. Here you will find an overview of all our security advice, which we update and supplement on a regular basis.
| CVE-ID | Datum | Kurzbeschreibung der Schwachstelle | Betroffene TA-Produkte |
| CVE-2026-34477 | -34478 | -34479 | -34480 | -34481 | 11.06.2026 | “Apache log4j” – Attackers can exploit several vulnerabilities to manipulate files. | No impact on TA products |
| CVE-2026-41651 | 13.05.2026 | „PackageKit“ – A TOCTOU race condition in versions 1.0.2–1.3.4 allows local users to install packages as root, resulting in a local privilege escalation | No impact on TA products |
| CVE-2025-14847 | 04.02.2026 | „MongoBleed“ – Memory can be read due to incorrect processing of compressed MongoDB messages | No impact on TA products |
| CVE-2021-21783 | 16.08.2024 | Vulnerability leading to potential code execution in the Web Service Library plugin gSOAP | No impact on TA products |
| CVE-2024-4574 / CVE-2024-4577 | 10.07.2024 | Security vulnerabilities in PHP implementations and WordPress plugins could enable potential attacks | No impact on TA products |
| CVE-2024-3094 | 02.05.2024 | Backdoor in xz-Tools und -libraries on Linux | No impact on TA products |
| CVE-2024-22076 | 29.02.2024 | Potential vulnerability allowing unauthenticated remote code execution in the PHP script for aQrate | aQrate |
| CVE-2023-41835 | 22.01.2024 | Error with multipart uploads in the framework Apache Struts | No impact on TA products |
| CVE-2023-50916 | 11.01.2024 | Manipulating folder paths can expose authentication credentials | TA/UTAX Device Manager |
| CVE-2023-4863 | 30.11.2023 | Heap buffer overflow in the image library libwebp | No impact on TA products |
| CVE-2023-31543 | 30.11.2023 | Vulnerability in Python-Tool pipreqs | No impact on TA products |
| CVE-2023-4911 | 22.11.2023 | „Looney Tunables“ – Vulnerability in Loader of GNU C Library | No impact on TA products |
| CVE-2023-25954 | 27.09.2023 | Insecure data transmission can lead to the download of malicious files | TA Mobile Print (Android) |
| CVE-2023-38408 | 19.07.2023 | A vulnerability in OpenSSH's ssh-agent allows code execution via a manipulated PKCS#11 function | No impact on TA products |
| ScannerVision | 19.07.2023 | Vulnerability in ScannerVision's PostScript processing function that allows code execution via the “Ghostscript” PDF library | ScannerVision |
| CVE-2023-34259 / 34260 / 34261 | 18.07.2023 | Security vulnerabilities in the web interface of printers/MFPs | TA Printers and Multifunction Systems |
| CVE-2023-36664 | 11.07.2023 | Critical vulnerability in the PDF library Ghostscript | No impact on TA products |
| CVE-2023-38634 | 24.05.2023 | Authorization vulnerability in the Windows KX printer driver | KX Printer Driver inkl. Status Monitor / TA Fleetmanager NetGateway / Device Manager / TA Cloud Print and Scan Desktop client / TA Smart Information Manager (TASIM) |
| CVE-2021-31769 | 17.03.2023 | Security vulnerabilities in the web application aQrate | aQrate |
| CVE-2021-43551 / 43552 | 06.01.2023 | Vulnerabilities in third-party software (PI Vision / Patient Information Center iX) | No impact on TA products |
| CVE-2022-41798 / 41807 / 41830 | 11.11.2022 | Deficiencies in session management, inadequate authentication, and a cross-site scripting vulnerability were identified in the Command Center | TA Printers and Multifunction Systems |
| CVE-2022-42889 | 03.11.2022 | Potential injection of malicious code via a vulnerability in Apache Common Text | No impact on TA products |
| CVE-2022-1026 | 04.04.2022 | SOAP interface may disclose address book data without authentication | TA Multifunction Systems |
| CVE-2022-22950 / 22963 / 22965 | 01.04.2022 | „Spring4Shell“ – Vulnerability in Spring-Framework | Kofax AutoStore |
| CVE-2021-44224 / 44790 | 20.12.2021 | Vulnerability in Apache HTTP Server | No impact on TA products |
| CVE-2021-44228 / 45046 / 45105 | 15.12.2021 | „Log4Shell“ – Critical RCE vulnerabilities in Log4j | enaio®, yuuvis® RAD und yuuvis® Momentum / Kofax Autostore / TASIM Server / Lizenzserver für TASIM und TA Capture Manager |
| CVE-2021-39237 / 39238 | 07.12.2021 | Vulnerability in HP MFP M725z | No impact on TA products |
| CVE-2021-42013 | 18.10.2021 | Path-Traversal / Vulnerability in Apache HTTP Server | No impact on TA products |
| CVE-2021-22156 | 27.08.2021 | Vulnerability in the BlackBerry QNX operating system | No impact on TA products |
| CVE-2021-34481 | 16.08.2021 | Administrator access is required to install and configure printer drivers | No impact on TA products |
| CVE-2021-33764 | 14.07.2021 | Vulnerability in Windows Key Distribution Center | No impact on TA products |
| CVE-2019-13195 – CVE-2019-13206 | 30.08.2019 | Multiple Vulnerabilities (XSS, CSRF, Path Traversal, Broken Access Control, Potential Buffer Overflow) | TA P-C2655w MFP |
| „Shellshock“ | 05.12.2014 | Vulnerabiity in GNU Bash („Shellshock“) | EFI™ Fiery Printing System(s) / TA Cockpit / UTAX Smart |
| Embedded Web Server | 2014 | XSS vulnerability in the embedded web server of multifunction devices and printers | TA Printers and Multifunction Systems |