# CASCA evidence receipt — CVE-2023-4911

- Generation: `gen-409cbd0c74ff4feb70e4944e6b98ce40`
- As known: 2026-07-21T08:13:17.697275+00:00
- Comparison: gen-56ccdaf914f7b4be95b689ccae7dc20d
- Score policy: public-priority-v1.0.1
- Conflict: not observed in this generation

## Source assertions

- **CISA-ADP** (independent_enrichment): container — CISA ADP Vulnrichment
  - Observed: 2026-07-19T04:27:06.398189+00:00
  - Citation: https://www.cve.org/CVERecord?id=CVE-2023-4911
- **CVE** (derivative_copy): container — CVE Program Container
  - Observed: 2026-07-19T04:27:06.398189+00:00
  - Citation: https://www.cve.org/CVERecord?id=CVE-2023-4911
- **redhat** (original_assertion): container — Glibc: buffer overflow in ld.so leading to privilege escalation
  - Observed: 2026-07-19T04:27:06.398189+00:00
  - Citation: https://www.cve.org/CVERecord?id=CVE-2023-4911
- **siemens-SADP** (unknown_origin): container — Container present
  - Observed: 2026-07-19T04:27:06.398189+00:00
  - Citation: https://www.cve.org/CVERecord?id=CVE-2023-4911
- **CISA KEV** (original_assertion): observed_exploitation — GNU C Library Buffer Overflow Vulnerability
  - Observed: 2026-07-19T04:54:04.25158+00:00
  - Citation: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- **FIRST EPSS** (original_assertion): model_probability — Probability 0.814220000000; percentile 0.995980000000
  - Observed: 2026-07-19T04:54:35.756809+00:00
  - Citation: https://www.first.org/epss/data_stats.html

## CVSS assessments

- **nvd@nist.gov** (Primary, CVSS 3.1): 7.8 — score eligible
  - Evidence class: nvd_enrichment_exact; source rank: 0
  - Validation: valid_match
  - Vector: `CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`
- **secalert@redhat.com** (Secondary, CVSS 3.1): 7.8 — score eligible
  - Evidence class: exact_record_cna; source rank: 1
  - Validation: valid_match
  - Vector: `CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`
- **redhat** (unknown, CVSS 3.1): 7.8 — display only
  - Evidence class: direct_cve_record_display_only; source rank: not applicable
  - Validation: display-only direct record assessment
  - Vector: `CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`

## Applicability scope

- **Red Hat · Red Hat Enterprise Linux 6** (direct_source; unknown)
  - Versions: []
- **Red Hat · Red Hat Enterprise Linux 7** (direct_source; unknown)
  - Versions: []
- **Red Hat · Red Hat Enterprise Linux 7** (direct_source; unknown)
  - Versions: []
- **Red Hat · Red Hat Enterprise Linux 8** (direct_source; unknown)
  - Versions: [{"status": "unaffected", "version": "0:2.28-225.el8_8.6", "lessThan": "*", "versionType": "rpm"}]
- **Red Hat · Red Hat Enterprise Linux 8** (direct_source; unknown)
  - Versions: [{"status": "unaffected", "version": "0:2.28-225.el8_8.6", "lessThan": "*", "versionType": "rpm"}]
- **Red Hat · Red Hat Enterprise Linux 8.6 Extended Update Support** (direct_source; unknown)
  - Versions: [{"status": "unaffected", "version": "0:2.28-189.6.el8_6", "lessThan": "*", "versionType": "rpm"}]
- **Red Hat · Red Hat Enterprise Linux 9** (direct_source; unknown)
  - Versions: [{"status": "unaffected", "version": "0:2.34-60.el9_2.7", "lessThan": "*", "versionType": "rpm"}]
- **Red Hat · Red Hat Enterprise Linux 9** (direct_source; unknown)
  - Versions: [{"status": "unaffected", "version": "0:2.34-60.el9_2.7", "lessThan": "*", "versionType": "rpm"}]
- **Red Hat · Red Hat Enterprise Linux 9.0 Extended Update Support** (direct_source; unknown)
  - Versions: [{"status": "unaffected", "version": "0:2.34-28.el9_0.4", "lessThan": "*", "versionType": "rpm"}]
- **Red Hat · Red Hat Virtualization 4 for Red Hat Enterprise Linux 8** (direct_source; unknown)
  - Versions: [{"status": "unaffected", "version": "0:4.5.3-202312060823_8.6", "lessThan": "*", "versionType": "rpm"}]
- **Red Hat · Red Hat Virtualization 4 for Red Hat Enterprise Linux 8** (direct_source; unknown)
  - Versions: [{"status": "unaffected", "version": "0:2.28-189.6.el8_6", "lessThan": "*", "versionType": "rpm"}]
- **Red Hat · Red Hat Virtualization 4 for Red Hat Enterprise Linux 8** (direct_source; unknown)
  - Versions: [{"status": "unaffected", "version": "0:4.5.3-10.el8ev", "lessThan": "*", "versionType": "rpm"}]
- **Siemens · SIMATIC S7-1500 CPU 1518-4 PN/DP MFP** (direct_source; unknown)
  - Versions: [{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]
- **Siemens · SIMATIC S7-1500 CPU 1518-4 PN/DP MFP** (direct_source; unknown)
  - Versions: [{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]
- **Siemens · SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP** (direct_source; unknown)
  - Versions: [{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]
- **Siemens · SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP** (direct_source; unknown)
  - Versions: [{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]
- **Siemens · SIPLUS S7-1500 CPU 1518-4 PN/DP MFP** (direct_source; unknown)
  - Versions: [{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]
- **Vendor not asserted · Product not asserted** (direct_source; unknown)
  - Versions: [{"status": "affected", "version": "2.34", "lessThan": "2.39", "versionType": "custom"}]
- **canonical · ubuntu_linux** (vulnerable_target; supported)
  - Versions: Version 22.04; Version 23.04
  - Canonical identity: `product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*`
- **debian · debian_linux** (vulnerable_target; supported)
  - Versions: Version 11.0; Version 12.0
  - Canonical identity: `product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*`
- **fedoraproject · fedora** (vulnerable_target; supported)
  - Versions: Version 37; Version 38; Version 39
  - Canonical identity: `product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*`
- **gnu · glibc** (vulnerable_target; supported)
  - Versions: Any version (unconstrained) (>= 2.34, < 2.39)
  - Canonical identity: `product-65ad58d9be95aee69193bfee5d43d39b1b0bde729796531951ee6e2f71f191cb`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*`
- **netapp · bootstrap_os** (vulnerable_target; supported)
  - Versions: Version not applicable
  - Canonical identity: `product-c79e30c6ed7acc5d7d83b9d9dce7e90bfad6e78e29ab0723ece2f95db88f8029`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*`
- **netapp · h300s** (environmental_constraint; constrained)
  - Versions: Version not applicable
  - Canonical identity: `product-5b787f6fb0dbffca7d5383cfa87cd93654a14ed60ccdd59abc2ba697fe7ead69`
  - Official link states: linked_exact
  - Criterion (linked_exact, environmental_constraint): `cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*`
- **netapp · h300s_firmware** (vulnerable_target; supported)
  - Versions: Version not applicable
  - Canonical identity: `product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*`
- **netapp · h410c** (environmental_constraint; constrained)
  - Versions: Version not applicable
  - Canonical identity: `product-19a4460172d592ee30b338581dced13baf393eedf54989f7303c0971a7aa6832`
  - Official link states: linked_exact
  - Criterion (linked_exact, environmental_constraint): `cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*`
- **netapp · h410c_firmware** (vulnerable_target; supported)
  - Versions: Version not applicable
  - Canonical identity: `product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045a`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*`
- **netapp · h410s** (environmental_constraint; constrained)
  - Versions: Version not applicable
  - Canonical identity: `product-ae7668c0a5adbc5d6599144484fb84400193fe6c73d0e6bb570cd2a233e63b35`
  - Official link states: linked_exact
  - Criterion (linked_exact, environmental_constraint): `cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*`
- **netapp · h410s_firmware** (vulnerable_target; supported)
  - Versions: Version not applicable
  - Canonical identity: `product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481ae`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*`
- **netapp · h500s** (environmental_constraint; constrained)
  - Versions: Version not applicable
  - Canonical identity: `product-4c7f1f62606e18f71887f5954346c3f8c8376e418a089dca8282922aa180aff3`
  - Official link states: linked_exact
  - Criterion (linked_exact, environmental_constraint): `cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*`
- **netapp · h500s_firmware** (vulnerable_target; supported)
  - Versions: Version not applicable
  - Canonical identity: `product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6a`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*`
- **netapp · h700s** (environmental_constraint; constrained)
  - Versions: Version not applicable
  - Canonical identity: `product-fcd38a3bd0a96c349925cecfd0d22ecf9836f21d88da8f545d6938975aa84275`
  - Official link states: linked_exact
  - Criterion (linked_exact, environmental_constraint): `cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*`
- **netapp · h700s_firmware** (vulnerable_target; supported)
  - Versions: Version not applicable
  - Canonical identity: `product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6d`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*`
- **netapp · hci_compute_node** (environmental_constraint; constrained)
  - Versions: Version not applicable
  - Canonical identity: `product-ac128f79df6958432aba953aa4fde55d70b2ccbfc258439c013b541010526631`
  - Official link states: linked_exact
  - Criterion (linked_exact, environmental_constraint): `cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*`
- **netapp · ontap_select_deploy_administration_utility** (vulnerable_target; supported)
  - Versions: Version not applicable
  - Canonical identity: `product-a29b5595b3d2a9b5738f4a4515b77cf292f7915044138b7e9367b90ddc00d096`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*`
- **redhat · codeready_linux_builder** (vulnerable_target; supported)
  - Versions: Version 9.0
  - Canonical identity: `product-5eabef33289b791d9a3247dd63dbd3db38ba7d17d36e7e6b97c60658d9c8e2c8`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder:9.0:*:*:*:*:*:*:*`
- **redhat · codeready_linux_builder_eus** (vulnerable_target; supported)
  - Versions: Version 8.6; Version 9.2; Version 9.4; Version 9.6
  - Canonical identity: `product-84030d766658c17495bdbc091c964ac1d5a4a9ac59b713addcf94ef9ae692836`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_eus:9.4:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_eus:9.2:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_eus:8.6:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_eus:9.6:*:*:*:*:*:*:*`
- **redhat · codeready_linux_builder_for_arm64** (vulnerable_target; supported)
  - Versions: Version 9.0_aarch64
  - Canonical identity: `product-55c79a3110dcb66254ae9d1a443809916ae8420dace75455bc0fdbcf9b04cb6a`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_arm64:9.0_aarch64:*:*:*:*:*:*:*`
- **redhat · codeready_linux_builder_for_arm64_eus** (vulnerable_target; supported)
  - Versions: Version 8.6; Version 9.2_aarch64; Version 9.4_aarch64; Version 9.6_aarch64
  - Canonical identity: `product-aaa2bb3b641aad5c2982a3c03b2f1df21a2506ac0d8a27fdee572af90d36f203`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_arm64_eus:9.4_aarch64:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_arm64_eus:9.2_aarch64:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_arm64_eus:9.6_aarch64:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_arm64_eus:8.6:*:*:*:*:*:*:*`
- **redhat · codeready_linux_builder_for_ibm_z_systems** (vulnerable_target; supported)
  - Versions: Version 9.0_s390x
  - Canonical identity: `product-7aec7957e3121391f4443eb4bf8f5cc25eecb5871e114401091e27e6bcc1a414`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*`
- **redhat · codeready_linux_builder_for_ibm_z_systems_eus** (vulnerable_target; supported)
  - Versions: Version 8.6; Version 9.2_s390x; Version 9.4_s390x; Version 9.6_s390x
  - Canonical identity: `product-f3a4a3479acb68a8ee1edf6cfd717b49ddd1780419c426d1b2f5450061435237`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems_eus:9.6_s390x:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems_eus:9.4_s390x:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems_eus:9.2_s390x:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems_eus:8.6:*:*:*:*:*:*:*`
- **redhat · codeready_linux_builder_for_power_little_endian** (vulnerable_target; supported)
  - Versions: Version 9.0_ppc64le
  - Canonical identity: `product-dce6b2225fa5e56152bdc66540e68bf243b135fd00684a7262378fbfd0331e98`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian:9.0_ppc64le:*:*:*:*:*:*:*`
- **redhat · codeready_linux_builder_for_power_little_endian_eus** (vulnerable_target; supported)
  - Versions: Version 8.6; Version 9.2_ppc64le; Version 9.4_ppc64le; Version 9.6_ppc64le
  - Canonical identity: `product-033988d8044dec156a49f5acd0582a6c2ae55446b339ee0706acfa8ca3732935`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:9.6_ppc64le:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:9.4_ppc64le:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:9.2_ppc64le:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:8.6:*:*:*:*:*:*:*`
- **redhat · enterprise_linux** (vulnerable_target; supported)
  - Versions: Version 8.0; Version 9.0
  - Canonical identity: `product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_eus** (vulnerable_target; supported)
  - Versions: Version 8.6; Version 9.2; Version 9.4; Version 9.6
  - Canonical identity: `product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_eus:9.6:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_eus:9.2:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_eus:9.4:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_for_arm_64** (vulnerable_target; supported)
  - Versions: Version 9.0_aarch64
  - Canonical identity: `product-5b647cbf10edba654fbfb5f3617b5887cae2cdbd5242317dd9286e31cb74c078`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_for_arm_64_eus** (vulnerable_target; supported)
  - Versions: Version 8.6_aarch64; Version 9.2_aarch64; Version 9.4_aarch64; Version 9.6_aarch64
  - Canonical identity: `product-19e25a323a33d2e95ae9af9c6f5d3c68dd2ffbbccb9a61583d6723e58fce1183`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:9.4_aarch64:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:9.2_aarch64:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:9.6_aarch64:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.6_aarch64:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_for_ibm_z_systems** (vulnerable_target; supported)
  - Versions: Version 9.0_s390x
  - Canonical identity: `product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_for_ibm_z_systems_eus** (vulnerable_target; supported)
  - Versions: Version 9.2_s390x; Version 9.4_s390x; Version 9.6_s390x
  - Canonical identity: `product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fd`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.4_s390x:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.6_s390x:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.2_s390x:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_for_ibm_z_systems_eus_s390x** (vulnerable_target; supported)
  - Versions: Version 8.6
  - Canonical identity: `product-7ce3aa9d5ccf00dbe1d056c7af556a21690db3daba9e04563b174c187d08062d`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus_s390x:8.6:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_for_power_big_endian_eus** (vulnerable_target; supported)
  - Versions: Version 8.6_ppc64le
  - Canonical identity: `product-c09e1a6c06a60f75d4f5a3a91108bcb8e8b7418b4d0bcbe56608e9eba3cd934b`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:8.6_ppc64le:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_for_power_little_endian** (vulnerable_target; supported)
  - Versions: Version 9.0_ppc64le
  - Canonical identity: `product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:9.0_ppc64le:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_for_power_little_endian_eus** (vulnerable_target; supported)
  - Versions: Version 9.2_ppc64le; Version 9.4_ppc64le; Version 9.6_ppc64le
  - Canonical identity: `product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.6_ppc64le:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.4_ppc64le:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.2_ppc64le:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_server_aus** (vulnerable_target; supported)
  - Versions: Version 8.6; Version 9.2; Version 9.4; Version 9.6
  - Canonical identity: `product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_server_aus:9.2:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_server_aus:9.6:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_server_aus:9.4:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions** (vulnerable_target; supported)
  - Versions: Version 9.2_ppc64le; Version 9.4_ppc64le; Version 9.6_ppc64le
  - Canonical identity: `product-7aac0d6df4011739a665cef59b909f27ef0f5f1f717c6cf81d56972ed234ca1c`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.4_ppc64le:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.2_ppc64le:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.6_ppc64le:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_server_tus** (vulnerable_target; supported)
  - Versions: Version 8.6
  - Canonical identity: `product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71da`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*`
- **redhat · enterprise_linux_update_services_for_sap_solutions** (vulnerable_target; supported)
  - Versions: Version 9.2; Version 9.4; Version 9.6
  - Canonical identity: `product-e8ced5e85118fc9f9f1278beed5b7649193508cd851d4301a339783d96fde4d0`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.6:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:*`
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.4:*:*:*:*:*:*:*`
- **redhat · virtualization** (vulnerable_target; supported)
  - Versions: Version 4.0
  - Canonical identity: `product-bc21aa5dab2a412aef9570b514ef0e2d033cf0ebc75eadff51969247fea73111`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*`
- **redhat · virtualization_host** (vulnerable_target; supported)
  - Versions: Version 4.0
  - Canonical identity: `product-6077d17fbbe710b7e004df2ce68ca2ecda6ca6818bc290d21e2eb259438463ba`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*`
- **siemens · simatic_s7-1500_cpu_1518-4_pn/dp_mfp** (environmental_constraint; constrained)
  - Versions: Version not applicable
  - Canonical identity: `product-bd9d8a94b2b1f9a7c7221871fcf41bb111b3912db7caf5fca8a57317b39af41b`
  - Official link states: linked_exact
  - Criterion (linked_exact, environmental_constraint): `cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\/dp_mfp:-:*:*:*:*:*:*:*`
- **siemens · simatic_s7-1500_cpu_1518-4_pn/dp_mfp_firmware** (vulnerable_target; supported)
  - Versions: Any version (unconstrained) (>= 3.1.5)
  - Canonical identity: `product-e3235f956d0b03fab02bfdf933b8dd4d42ff19662d2806bb68896fc45140504e`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:*`
- **siemens · simatic_s7-1500_cpu_1518f-4_pn/dp_mfp** (environmental_constraint; constrained)
  - Versions: Version not applicable
  - Canonical identity: `product-ce7d56719c6f8f8335481735de3a02d59f3c20affb819bc2d535899634dc5d67`
  - Official link states: linked_exact
  - Criterion (linked_exact, environmental_constraint): `cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp:-:*:*:*:*:*:*:*`
- **siemens · simatic_s7-1500_cpu_1518f-4_pn/dp_mfp_firmware** (vulnerable_target; supported)
  - Versions: Any version (unconstrained) (>= 3.1.5)
  - Canonical identity: `product-fdc70f3228f57dc527b2af77480c3fca34c64a0bd200746fb82fed5c93884222`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:*`
- **siemens · simatic_s7-1500_tm_mfp** (environmental_constraint; constrained)
  - Versions: Version not applicable
  - Canonical identity: `product-1873eb6129b640ae87453287e64d86a0ff0af921f83693bf58b4eb450fe1356c`
  - Official link states: linked_exact
  - Criterion (linked_exact, environmental_constraint): `cpe:2.3:h:siemens:simatic_s7-1500_tm_mfp:-:*:*:*:*:*:*:*`
- **siemens · simatic_s7-1500_tm_mfp_firmware** (vulnerable_target; supported)
  - Versions: Any version (unconstrained) (< 1.1)
  - Canonical identity: `product-fbf3d7a9bdbb9b8a6bf0819e767f17a55d5349b4a51f96fdeaff8c200f17d432`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:siemens:simatic_s7-1500_tm_mfp_firmware:*:*:*:*:*:*:*:*`
- **siemens · siplus_s7-1500_cpu_1518-4_pn/dp_mfp** (environmental_constraint; constrained)
  - Versions: Version not applicable
  - Canonical identity: `product-674b71d33a68b6a3b988858db841fe5172abf3d7805f72583c99057992191f7e`
  - Official link states: linked_exact
  - Criterion (linked_exact, environmental_constraint): `cpe:2.3:h:siemens:siplus_s7-1500_cpu_1518-4_pn\/dp_mfp:-:*:*:*:*:*:*:*`
- **siemens · siplus_s7-1500_cpu_1518-4_pn/dp_mfp_firmware** (vulnerable_target; supported)
  - Versions: Any version (unconstrained) (>= 3.1.5)
  - Canonical identity: `product-61b3b6bd164968eec028750df4dba593ae4b12f5cc56f27df25c3b8b443d1973`
  - Official link states: linked_exact
  - Criterion (linked_exact, vulnerable_target): `cpe:2.3:o:siemens:siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:*`

## Identity source boundaries

- **cpe_dictionary**: 1775266 records through 2026-07-21T06:45:29.809553+00:00
  - Run: `27d65b0f-b718-4b4f-bb79-c47c68d09dfa`
- **cpe_match**: 643502 records through 2026-07-21T08:13:17.697275+00:00
  - Run: `955dae73-7302-438b-aee1-058d7cc5d48e`

## Limitations and unknowns

- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.

Generated from CASCA normalized evidence. This receipt is not proof that an asset is affected, unaffected, safe, or fixed.
