CVE-2022-1096 Google V8 Open Source JavaScript Engine Vulnerability
The only Software Toolbox solution utilizing the Google V8 Open Source JavaScript Engine is specifically the Universal Device Driver for TOP Server, introduced in TOP Server Version 6.10 and 6.11. Your system is NOT vulnerable unless you are actively using the UDD in a TOP Server project (i.e. you have a channel and device configured actively using the Universal Device Driver). Simply having the UDD installed does NOT expose your system to this vulnerability.
- If you are following best practices of only installing the drivers you are actively using and those drivers do NOT include the UDD, your system is NOT affected.
- If you have performed a full installation of TOP Server V6.10 or V6.11 but DO NOT have any channels using the UDD, your system is NOT affected.
However, if you have the UDD installed and are concerned, it is recommended to run the TOP Server installation, perform a modification operation and deselect the Universal Device Driver, which will uninstall the driver completely. Development is actively working to address this vulnerability for anyone actively using the Universal Device Driver - as soon as an update is available, we will update this FAQ and notify all confirmed users of the Universal Device Driver.
No other Software Toolbox solutions or TOP Server drivers use the affected engine and, as such, are not vulnerable.