VARIoT news about IoT security

Related entries in the VARIoT vulnerabilities database: VAR-202301-0521

Trust: 4.25

Fetched: Aug. 2, 2023, 9:23 a.m., Published: June 2, 2023, midnight
Vulnerabilities: information disclosure, denial of service, code execution
Affected productsExternal IDs
vendor: google model: pixel
vendor: google model: android
vendor: motorola model: motorola
vendor: motorola model: android
vendor: samsung model: mobile
vendor: samsung model: notes
vendor: samsung model: note
vendor: huawei model: huawei
db: NVD ids: CVE-2022-40516, CVE-2023-21137, CVE-2022-33264, CVE-2023-21095, CVE-2023-21120, CVE-2022-40538, CVE-2023-21135, CVE-2023-21127, CVE-2022-22060, CVE-2023-21124, CVE-2023-21115, CVE-2022-28349, CVE-2022-22706, CVE-2023-21101, CVE-2023-21143, CVE-2023-21658, CVE-2023-21128, CVE-2021-0701, CVE-2021-0945, CVE-2022-48390, CVE-2022-48391, CVE-2023-21141, CVE-2022-33251, CVE-2023-21142, CVE-2022-40517, CVE-2022-46781, CVE-2023-21105, CVE-2022-33257, CVE-2023-21131, CVE-2022-48438, CVE-2023-21122, CVE-2023-21129, CVE-2022-48392, CVE-2023-21130, CVE-2022-40523, CVE-2023-21661, CVE-2022-40533, CVE-2022-40520, CVE-2023-21121, CVE-2023-21628, CVE-2023-21108, CVE-2022-40536, CVE-2023-21139, CVE-2022-40521, CVE-2023-21659, CVE-2023-21138, CVE-2023-21123, CVE-2023-21144, CVE-2023-21126, CVE-2022-40529, CVE-2023-21136

Trust: 3.25

Fetched: Aug. 2, 2023, 9:23 a.m., Published: Aug. 1, 2023, midnight
Vulnerabilities: code execution
Affected productsExternal IDs

Trust: 5.5

Fetched: Aug. 2, 2023, 9:22 a.m., Published: July 13, 2023, midnight
Vulnerabilities: command injection, os command injection
Affected productsExternal IDs
vendor: enphase energy model: envoy
vendor: enphase model: envoy
db: NVD ids: CVE-2023-33869
Related entries in the VARIoT vulnerabilities database: VAR-202307-0076

Trust: 4.25

Fetched: Aug. 2, 2023, 9:21 a.m., Published: July 2, 2023, midnight
Vulnerabilities: information disclosure, denial of service, code execution
Affected productsExternal IDs
vendor: google model: pixel
vendor: google model: wifi
vendor: google model: android
vendor: motorola model: motorola
vendor: motorola model: android
vendor: samsung model: mobile
vendor: samsung model: notes
vendor: samsung model: note
vendor: huawei model: huawei
db: NVD ids: CVE-2023-26083, CVE-2023-21145, CVE-2021-0948, CVE-2023-21254, CVE-2023-21245, CVE-2023-21250, CVE-2023-21243, CVE-2023-21255, CVE-2023-21087, CVE-2023-21241, CVE-2023-21262, CVE-2023-21248, CVE-2023-21247, CVE-2023-21246, CVE-2022-28350, CVE-2023-21629, CVE-2023-22667, CVE-2023-20754, CVE-2023-20942, CVE-2023-28147, CVE-2023-21256, CVE-2023-20910, CVE-2023-21240, CVE-2023-21257, CVE-2022-42703, CVE-2022-27406, CVE-2023-20918, CVE-2023-25012, CVE-2023-21251, CVE-2023-21631, CVE-2023-21249, CVE-2023-21239, CVE-2022-27405, CVE-2023-20755, CVE-2023-21238, CVE-2023-2136, CVE-2021-29256

Trust: 3.0

Fetched: Aug. 2, 2023, 9:21 a.m., Published: July 30, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2023-35078, CVE-2023-35081

Trust: 3.75

Fetched: Aug. 2, 2023, 9:20 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: series
vendor: cisco model: spa112
db: NVD ids: CVE-2023-20126

Trust: 5.5

Fetched: Aug. 2, 2023, 9:20 a.m., Published: June 26, 2023, 12:20 p.m.
Vulnerabilities: memory corruption, integer overflow, code execution
Affected productsExternal IDs
vendor: apple model: watchos
vendor: apple model: macos
vendor: apple model: webkit
vendor: apple model: safari
vendor: apple model: iphone
db: NVD ids: CVE-2023-32435, CVE-2023-32434, CVE-2023-32439

Trust: 5.0

Fetched: Aug. 2, 2023, 9:19 a.m., Published: June 7, 2023, 11:25 a.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: cisco model: unified communications manager
vendor: cisco model: cisco unified communications manager
vendor: cisco model: unified communications
Related entries in the VARIoT vulnerabilities database: VAR-202304-2073

Trust: 3.0

Fetched: Aug. 2, 2023, 9:19 a.m., Published: July 13, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2023-28771

Trust: 3.5

Fetched: Aug. 2, 2023, 9:18 a.m., Published: Jan. 10, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: siemens model: simotion
vendor: siemens model: simotion p320
db: NVD ids: CVE-2023-27465

Trust: 3.25

Fetched: Aug. 2, 2023, 9:16 a.m., Published: May 2, 2019, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs

Trust: 5.0

Fetched: Aug. 1, 2023, 9:31 a.m., Published: July 28, 2023, 6:32 p.m.
Vulnerabilities: cross-site scripting
Affected productsExternal IDs
db: NVD ids: CVE-2023-38750, CVE-2023-0464

Trust: 4.0

Fetched: Aug. 1, 2023, 9:30 a.m., Published: July 31, 2023, 12:58 p.m.
Vulnerabilities: path traversal
Affected productsExternal IDs
db: NVD ids: CVE-2023-35081, CVE-2023-35078

Trust: 3.25

Fetched: Aug. 1, 2023, 9:28 a.m., Published: Jan. 1, 2050, midnight
Vulnerabilities: privilege escalation, code execution
Affected productsExternal IDs
vendor: apple model: icloud
vendor: apple model: itunes
vendor: apple model: macos
vendor: apple model: webkit

Trust: 4.75

Fetched: Aug. 1, 2023, 9:28 a.m., Published: July 27, 2023, midnight
Vulnerabilities: privilege escalation, directory traversal, path traversal
Affected productsExternal IDs
db: NVD ids: CVE-2022-3703, CVE-2022-40981, CVE-2022-41607
Related entries in the VARIoT vulnerabilities database: VAR-202306-1706, VAR-202305-2074, VAR-201507-0039, VAR-202306-1705

Trust: 3.5

Fetched: Aug. 1, 2023, 9:27 a.m., Published: June 15, 2023, 3:33 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: schneider model: modbus
vendor: schneider electric model: modbus
vendor: wago model: bacnet/ip
vendor: wago model: ethernet
vendor: codesys model: control
vendor: codesys model: runtime
vendor: codesys model: codesys
db: NVD ids: CVE-2023-1619, CVE-2022-46680, CVE-2015-5374, CVE-2023-1620

Trust: 3.5

Fetched: Aug. 1, 2023, 9:27 a.m., Published: Aug. 2, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: barracuda model: barracuda
vendor: barracuda model: running
vendor: trend model: security
db: NVD ids: CVE-2023-27997, CVE-2023-35708, CVE-2023-2868

Trust: 4.75

Fetched: Aug. 1, 2023, 9:26 a.m., Published: June 30, 2023, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2023-31222
Related entries in the VARIoT vulnerabilities database: VAR-202212-1132, VAR-201707-1052, VAR-201711-0635, VAR-201803-1048

Trust: 5.0

Fetched: Aug. 1, 2023, 9:25 a.m., Published: June 15, 2023, 4:46 a.m.
Vulnerabilities: denial of service, code execution, buffer overflow
Affected productsExternal IDs
vendor: ubiquiti model: unifi
vendor: mikrotik model: routers
vendor: mikrotik model: router
vendor: fiberhome model: routers
vendor: fiberhome model: router
vendor: tp-link model: routers
vendor: tp-link model: gateway
vendor: cisco model: routers
vendor: cisco model: cisco routers
vendor: cisco model: router
vendor: huawei model: huawei
vendor: huawei model: huawei home gateway
db: NVD ids: CVE-2021-21974, CVE-2022-42475, CVE-2023-22952, CVE-2021-21972, CVE-2017-6736, CVE-2017-16959, CVE-2019-5544, CVE-2022-37042, CVE-2017-17215, CVE-2020-3992, CVE-2022-40734, CVE-2022-27925
Related entries in the VARIoT vulnerabilities database: VAR-202305-2285, VAR-202304-2073, VAR-202305-2121

Trust: 4.75

Fetched: Aug. 1, 2023, 9:24 a.m., Published: June 5, 2023, 12:41 p.m.
Vulnerabilities: code execution, command execution
Affected productsExternal IDs
vendor: zyxel model: zywall
db: NVD ids: CVE-2023-33010, CVE-2023-28771, CVE-2023-33009