VARIoT news about IoT security

Trust: 3.25

Fetched: March 21, 2025, 9:31 a.m., Published: Feb. 28, 2025, 9:47 a.m.
Vulnerabilities: default credentials, sql injection
Affected productsExternal IDs

Trust: 5.0

Fetched: March 21, 2025, 9:30 a.m., Published: Feb. 26, 2025, 3:52 p.m.
Vulnerabilities: command injection
Affected productsExternal IDs
vendor: cisco model: nexus
vendor: cisco model: nexus 7000
vendor: cisco model: nexus 9000 series
vendor: cisco model: nx-os software
vendor: cisco model: nx-os
vendor: cisco model: nexus 9000
vendor: cisco model: series
vendor: cisco model: series switches
vendor: cisco model: cisco nx-os
vendor: cisco model: nexus 3000

Trust: 4.25

Fetched: March 21, 2025, 9:29 a.m., Published: -
Vulnerabilities: privilege elevation
Affected productsExternal IDs
db: NVD ids: CVE-2025-20636

Trust: 4.0

Fetched: March 21, 2025, 9:27 a.m., Published: Jan. 21, 7355, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: canonical model: ubuntu
db: NVD ids: CVE-2024-47532, CVE-2025-22153, CVE-2023-41039, CVE-2023-37271

Trust: 5.0

Fetched: March 21, 2025, 9:26 a.m., Published: Jan. 21, 7279, midnight
Vulnerabilities: code execution, denial of service, cross-site scripting
Affected productsExternal IDs
vendor: canonical model: ubuntu

Trust: 3.75

Fetched: March 21, 2025, 9:25 a.m., Published: March 7, 2025, midnight
Vulnerabilities: command injection
Affected productsExternal IDs
db: NVD ids: CVE-2024-12009, CVE-2024-12010, CVE-2024-11253
Related entries in the VARIoT vulnerabilities database: VAR-202501-3604, VAR-202501-3603

Trust: 4.5

Fetched: March 21, 2025, 9:25 a.m., Published: March 19, 2025, 1:20 p.m.
Vulnerabilities: command injection, os command injection, command execution
Affected productsExternal IDs
vendor: myscada model: mypro
vendor: rapid model: scada
db: NVD ids: CVE-2025-200619, CVE-2025-20061, CVE-2025-200149, CVE-2025-20014

Trust: 3.5

Fetched: March 21, 2025, 9:23 a.m., Published: March 11, 2025, 12:50 p.m.
Vulnerabilities: code execution, code injection, privilege escalation...
Affected productsExternal IDs
vendor: essential model: phone

Trust: 3.75

Fetched: March 21, 2025, 9:21 a.m., Published: March 20, 2025, 11:26 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: dahua model: network camera
vendor: dahua model: camera
vendor: hikvision model: hikvision
db: NVD ids: CVE-2021-36260

Trust: 3.0

Fetched: March 21, 2025, 9:21 a.m., Published: March 18, 2025, 5:36 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: android

Trust: 3.25

Fetched: March 21, 2025, 9:20 a.m., Published: Jan. 21, 7287, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: canonical model: ubuntu

Trust: 4.0

Fetched: March 21, 2025, 9:19 a.m., Published: -
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2025-27595, CVE-2025-27593, CVE-2025-27594

Trust: 5.0

Fetched: March 21, 2025, 9:19 a.m., Published: March 11, 2025, 5:16 p.m.
Vulnerabilities: privilege escalation, improper access control
Affected productsExternal IDs
db: NVD ids: CVE-2025-24076

Trust: 4.25

Fetched: March 21, 2025, 9:19 a.m., Published: March 10, 2025, 7:17 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2025-24043

Trust: 4.25

Fetched: March 21, 2025, 9:18 a.m., Published: Jan. 21, 7353, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: canonical model: ubuntu

Trust: 4.25

Fetched: March 21, 2025, 9:17 a.m., Published: Feb. 21, 7275, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: canonical model: ubuntu

Trust: 4.25

Fetched: March 21, 2025, 9:17 a.m., Published: March 15, 2025, 7:18 p.m.
Vulnerabilities: sql injection, cross-site scripting, buffer overflow
Affected productsExternal IDs
vendor: essential model: phone
vendor: apple model: safari
vendor: apple model: watch
vendor: apple model: iphone

Trust: 5.5

Fetched: March 21, 2025, 9:16 a.m., Published: March 12, 2025, 1 p.m.
Vulnerabilities: feature bypass, code execution, information disclosure...
Affected productsExternal IDs
vendor: trend model: security
vendor: trend micro model: security
db: NVD ids: CVE-2025-24984, CVE-2025-24991, CVE-2025-26630, CVE-2025-26633, CVE-2025-24985, CVE-2025-24983, CVE-2025-24993

Trust: 5.75

Fetched: March 21, 2025, 9:16 a.m., Published: March 20, 2025, 8:22 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: mitel model: micollab
db: NVD ids: CVE-2025-23120
Related entries in the VARIoT vulnerabilities database: VAR-202210-0198, VAR-201906-0815

Trust: 4.75

Fetched: March 21, 2025, 9:15 a.m., Published: March 19, 2025, 3:21 p.m.
Vulnerabilities: path traversal, authentication bypass
Affected productsExternal IDs
vendor: fortigate model: fortios
db: NVD ids: CVE-2022-40684, CVE-2018-13379