{"api_version":"v1","generated_at":"2026-10-10T10:35:00+00:00","product":{"cve_count":1,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-blackberry-qnx-software-development-platform-sdp-qnx-os-for-medical-and-qnx-os-for-safety-cbc966b2a255","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"QNX Software Development Platform (SDP), QNX OS for Medical and QNX OS for Safety","next_cursor":null,"observations":[{"affected":"QNX SDP 6.5.0 SP1 and earlier; QNX OS for Medical 1.1 and earlier; QNX OS for Safety 1.0.1 and earlier","affected_versions_present":true,"cve_id":"CVE-2021-22156","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-22156","fixed":"Updates have been released to address the identified vulnerability Customers are urged to upgrade to Niagara 4.10u1. These updates are available on the Schneider Electric Exchange https://ecoxpert.se.com/ or by contacting your sales support channel or by contacting the Schneider Electric support team at productsupport.NAM-BMS@schneider-electric.com It is important that all TAC I/A Series Niagara customers for all supported platforms update their systems with these releases to mitigate risk. If you have any questions, please contact your Schneider Electric support team at productsupport.NAM-BMS@schneider-electric.com. As always, we highly recommend that TAC I/A Series Niagara customers running on an unsupported platform (such as Niagara G3/AX) take action to update their systems to a supported platform, ideally the 4.10u1 release of Niagara Framework. In addition to updating your system, Schneider Electric recommends that customers with affected products take the following steps to protect themselves: \u2022 Review and validate the list of users who are authorized and who can authenticate to Niagara. \u2022 Allow only trained and trusted persons to have physical access to the system, including devices that have connection to the system though the Ethernet port. \u2022 Consider using a VPN or other means to ensure secure remote connections into the network where the system is located, If remote connections are enabled. \u2022 Sign all modules and program objects provided by third-party teams. Review the Niagara Hardening Guide https://community.exchange.se.com/t5/Building-Automation-Knowledge/I-A-Series-Niagara-4-Hardening-Guide-Tips-to-Secure-an-I-A/ta-p/159287 for techniques on securing your installation.","last_modified":"2025-08-22T15:20:31.911Z","patch_url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-313-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2021-313-05_BadAlloc_Vulnerabilities_Security_Notification.pdf","primary_source":"","published":"2021-08-17T18:35:38.000Z"}],"source_generated_at":"2026-10-10T06:21:41.304Z","vendor":"BlackBerry"}}
