Support
Security
Security Policy
TAKEBISHI CORPORATION has obtained ISO 27001 (ISMS) certification − a leading international standard for information security management systems − as the company believes it is important to manage and utilize its information assets safely and appropriately in a way that meets the trust that the customers and society put in the company along with their requirements.
Please see below for details.
Information Security Management Systems | TAKEBISHI CORPORATION
Security Vulnerabilities
DeviceXPlorer OPC Server
DeviceGateway
OPC Spider
Shared
DeviceXPlorer OPC Server
* You can scroll this table sideways.
Release Date Urgency |
Affected Version |
Contents |
---|---|---|
May 2023 |
6.0.0 - 6.7.0 |
Updated OpenSSL library version used in OPC UA server/client/HTTP client/MQTT client function from 1.1.1n to 1.1.1t. Update to DeviceXPlorer OPC Server Ver.6.8.0 or Ver.7.1.0 |
Jul. 2022 |
6.0.0 - 6.6.0 |
Updated the version from 1.1.1l to 1.1.1n of the OpenSSL library used in the OPC UA server / client function. Update to DeviceXPlorer OPC Server Ver.6.7.0. |
Dec. 2021 |
6.0.0 - 6.4.0 |
Updated the version from 1.02p to 1.1.1l of the OpenSSL library used in the OPC UA server / client function. Solution: |
Aug. 2021 |
6.0.0 - 6.3.0 |
Updated the version of the library (CodeMeterRuntime) from v7.20b to v7.21a used for license key activation. Cause: |
Aug. 2021 |
5.0.0,1 |
Fixed the problem that malicious attacker may cause to trigger a stack overflow and application clashed if OPC UA server function enable. |
DeviceGateway
* You can scroll this table sideways.
Release Date Urgency |
Affected Version |
Contents |
---|---|---|
Mar 2024 |
- 3.3.0 |
Updated SQLite library version used in Buffering function from 3.30.1 to 3.45.2 Solution: Update to DeviceGateway Ver.3.4.0 |
May 2023 |
- 3.2.0 |
Updated OpenSSL library version used in OPC UA server/client/HTTP client/MQTT client function from 1.1.1n to 1.1.1t Update to DeviceGateway Ver.3.2.1 |
Mar. 2022 |
- 3.0.3 |
Updated the version from 1.1.1l to 1.1.1n of the OpenSSL library used in the OPC UA server / client function. Update to DeviceGateway Ver.3.1.0 |
Oct. 2021 |
- 3.0.0 |
Updated the version from 1.02p to 1.1.1l of the OpenSSL library used in the OPC UA server / client function. Solution: Update to DeviceGateway Ver.3.0.1 |
OPC Spider
* You can scroll this table sideways.
Release Date Urgency |
Affected Version |
Contents |
---|---|---|
May 2023 |
- 1.2.1 |
In ScriptRunner, improved the password encryption for launchsettings files. Vulnerability: Solution: In ScriptRunner, after applying this patch, perform the following procedure to encrypt passwords again for all launch settings files:
To use the launch settings file in another environment, you must perform the above procedure again. In ScriptRunner for Amazon SQS, after applying this patch, perform the following procedure to encrypt passwords and secret keys again for all launch settings files and property files:
To use the launch settings file and the property file in another environment, you must perform the above procedure again. |
Shared
* You can scroll this table sideways.
Release Date Urgency |
Contents |
---|---|
Mar. 2022 |
Due to an affect on our products of a security update program dealing with a DCOM vulnerability (CVE-2021-26414), after applying the security update program, the OPC DA Client may be unable to connect with the OPC DA Server for DCOM communication using the following constructions:
※ Communication with OPC UA interface is not affected. Regarding affected productsThe OPC DA interface of the following products may be affected:
For details and solutions, please refer to the following link. Effect on our products for security update for vulnarebility in DCOM (CVE-2021-26414) |
Download Patches
Use this link to download the latest software patches which address security vulnerabilities:
Subscribe to Security Alerts
Security-related update information will be provided by email, so please register if you would like to receive such notifications.