← Telia Company cases
Bugzilla #1999296 Security Incident

Telia: Findings in 2025 ETSI Audit - Incident Report #1 – Vulnerability management

RESOLVED FIXED Telia Company
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Telia Company reported a non-conformity identified during their 2025 ETSI audit regarding the timely remediation of critical vulnerabilities. The vulnerabilities were discovered in penetration tests conducted on October 13, 2025, but were not addressed within the required 48-hour timeframe, as mandated by ETSI EN 319 401. Following the audit findings, Telia submitted a preliminary incident report on November 10, 2025, and a full report on November 21, 2025, detailing the incident and corrective actions taken. The CA implemented a remediation plan, including deploying a new server and conducting training to ensure compliance with vulnerability management requirements. The case has been resolved with all action items completed.

Model: gpt-4o-mini Generated: 2026-06-13 20:51 UTC Revised: 2026-06-16 18:19 UTC Confidence: 0.85 12 comments
Chronology
  1. Non-compliance start date identified
  2. Immediate remediation plan created and affected server shut down
  3. Incident report closed
Thread Activity
  1. Teliacompany representative — Preliminary incident report submitted detailing non-conformity regarding vulnerability management.
  2. Teliacompany representative — Full incident report submitted with detailed analysis and remediation steps.
  3. Teliacompany representative — All action items completed; preparing closure report.
  4. CCADB representative — Final call for comments on the incident report before closure.
Participants
Community commenter
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1689589 RESOLVED Self Reported Incident Security Incident Opened 2021-01-29 · Closed 2023-02-22 · 78% similar
Telia: Disallowed curve (P-521) in leaf certificate
#1965828 RESOLVED Self Reported Incident Security Incident Opened 2025-05-12 · Closed 2025-08-19 · 63% similar
SwissSign: OCSP outage
#1879602 RESOLVED Security Incident Self Reported Incident Opened 2024-02-09 · Closed 2024-07-19 · 60% similar
Entrust: OCSP response signed with SHA-1
#1577014 RESOLVED Security Incident Opened 2019-08-27 · Closed 2023-02-22 · 60% similar
DigiCert: OCSP services returns 1 byte
#2006711 RESOLVED Security Incident Opened 2025-12-17 · Closed 2026-02-11 · 60% similar
NAVER Cloud Trust Services: Encoding non-conformity in SCT extensions
#1446121 RESOLVED Self Reported Incident Security Incident Opened 2018-03-15 · Closed 2023-02-22 · 60% similar
IdenTrust: Improper encoding of wildcard certificate
#1882904 RESOLVED Security Incident Opened 2024-02-29 · Closed 2025-02-12 · 60% similar
Google Trust Services: Incorrect OCSP responses for new ICAs under test
#1970728 RESOLVED Security Incident Opened 2025-06-05 · Closed 2025-07-16 · 60% similar
eMudhra: Invalid CRL signatures

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action