Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY1 SECURITY RECORD

BlackBerry

QNX Software Development Platform (SDP), QNX OS for Medical and QNX OS for Safety

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2021-22156 17 Aug 2021 QNX SDP 6.5.0 SP1 and earlier; QNX OS for Medical 1.1 and earlier; QNX OS for Safety 1.0.1 and earlier Updates have been released to address the identified vulnerability Customers are urged to upgrade to Niagara 4.10u1. These updates are available on the Schneider Electric Exchange https://ecoxpert.se.com/ or by contacting your sales support channel or by contacting the Schneider Electric support team at productsupport.NAM-BMS@schneider-electric.com It is important that all TAC I/A Series Niagara customers for all supported platforms update their systems with these releases to mitigate risk. If you have any questions, please contact your Schneider Electric support team at productsupport.NAM-BMS@schneider-electric.com. As always, we highly recommend that TAC I/A Series Niagara customers running on an unsupported platform (such as Niagara G3/AX) take action to update their systems to a supported platform, ideally the 4.10u1 release of Niagara Framework. In addition to updating your system, Schneider Electric recommends that customers with affected products take the following steps to protect themselves: • Review and validate the list of users who are authorized and who can authenticate to Niagara. • Allow only trained and trusted persons to have physical access to the system, including devices that have connection to the system though the Ethernet port. • Consider using a VPN or other means to ensure secure remote connections into the network where the system is located, If remote connections are enabled. • Sign all modules and program objects provided by third-party teams. Review the Niagara Hardening Guide https://community.exchange.se.com/t5/Building-Automation-Knowledge/I-A-Series-Niagara-4-Hardening-Guide-Tips-to-Secure-an-I-A/ta-p/159287 for techniques on securing your installation. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.