VARIoT news about IoT security

Related entries in the VARIoT vulnerabilities database: VAR-202302-1097, VAR-202302-1169

Trust: 5.5

Fetched: Feb. 17, 2023, 9:29 a.m., Published: Feb. 14, 2023, 10:29 a.m.
Vulnerabilities: use after free, code execution
Affected productsExternal IDs
vendor: apple model: safari
vendor: apple model: ipad
vendor: apple model: ipad air
vendor: apple model: iphone
vendor: apple model: webkit
db: NVD ids: CVE-2023-23529, CVE-2023-23514

Trust: 4.25

Fetched: Feb. 17, 2023, 9:29 a.m., Published: Jan. 30, 2023, 10:45 p.m.
Vulnerabilities: sql injection
Affected productsExternal IDs
db: NVD ids: CVE-2022-27596
Related entries in the VARIoT vulnerabilities database: VAR-202211-0371

Trust: 5.75

Fetched: Feb. 17, 2023, 9:29 a.m., Published: Feb. 16, 2023, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: huawei model: mate
vendor: huawei model: mate 30 pro
vendor: huawei model: mate 30
vendor: huawei model: huawei
vendor: huawei model: emui
vendor: huawei model: huawei mate
db: NVD ids: CVE-2022-44563
Related entries in the VARIoT vulnerabilities database: VAR-202302-0213

Trust: 5.25

Fetched: Feb. 17, 2023, 9:28 a.m., Published: Feb. 17, 2023, midnight
Vulnerabilities: code execution, remote command injection, command injection
Affected productsExternal IDs
vendor: palo model: networks
vendor: palo alto networks model: networks
vendor: cisco model: ic3000
vendor: cisco model: routers
vendor: cisco model: industrial isrs
vendor: cisco model: series
vendor: cisco model: ir510 wpan
db: NVD ids: CVE-2023-20076, CVE-2021-35394
Related entries in the VARIoT vulnerabilities database: VAR-201505-0363, VAR-202002-1447, VAR-201705-3255, VAR-202006-1056, VAR-202206-0004

Trust: 5.75

Fetched: Feb. 17, 2023, 9:28 a.m., Published: Feb. 16, 2023, 1:56 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: palo alto networks model: networks
vendor: palo model: networks
db: NVD ids: CVE-2022-4257, CVE-2014-9727, CVE-2019-15107, CVE-2020-8515, CVE-2017-5173, CVE-2022-36267, CVE-2020-15415, CVE-2012-4869, CVE-2022-26134
Related entries in the VARIoT vulnerabilities database: VAR-202301-0630, VAR-202301-0629

Trust: 4.75

Fetched: Feb. 17, 2023, 9:27 a.m., Published: Feb. 10, 2023, 4:36 a.m.
Vulnerabilities: information disclosure, command injection, privilege escalation...
Affected productsExternal IDs
vendor: siemens model: automation license manager
db: NVD ids: CVE-2022-43513, CVE-2022-43514, CVE-2022-46650, CVE-2022-46649, CVE-2022-3703, CVE-2022-40981, CVE-2022-41607

Trust: 3.75

Fetched: Feb. 17, 2023, 9:27 a.m., Published: Feb. 15, 2023, 4:50 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: google model: android
vendor: google model: chrome
vendor: apple model: icloud
vendor: apple model: iphone

Trust: 3.0

Fetched: Feb. 17, 2023, 9:26 a.m., Published: Feb. 14, 2023, 8:29 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: macos
vendor: apple model: ipad
vendor: apple model: ipad air
vendor: apple model: iphone

Trust: 3.0

Fetched: Feb. 17, 2023, 9:26 a.m., Published: Feb. 16, 2023, 5 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: siemens model: automation license manager

Trust: 4.5

Fetched: Feb. 17, 2023, 9:22 a.m., Published: Feb. 16, 2023, 4:31 p.m.
Vulnerabilities: code execution, command injection, default credentials
Affected productsExternal IDs
db: NVD ids: CVE-2022-45701

Trust: 5.5

Fetched: Feb. 17, 2023, 9:21 a.m., Published: Feb. 2, 2023, 4:40 p.m.
Vulnerabilities: code execution, command injection, buffer overflow
Affected productsExternal IDs
vendor: asus model: routers
vendor: asus model: asus
db: NVD ids: CVE-2021-35394

Trust: 5.5

Fetched: Feb. 17, 2023, 9:20 a.m., Published: Dec. 5, 2022, 2:24 p.m.
Vulnerabilities: default password
Affected productsExternal IDs
vendor: palo alto networks model: networks
vendor: palo model: networks
db: NVD ids: CVE-2019-11687

Trust: 4.5

Fetched: Feb. 17, 2023, 9:20 a.m., Published: Feb. 15, 2023, 8:14 p.m.
Vulnerabilities: denial of service, buffer overflow
Affected productsExternal IDs
vendor: clamav model: clamav
vendor: cisco model: clamav

Trust: 5.25

Fetched: Feb. 17, 2023, 9:19 a.m., Published: Feb. 15, 2023, 3:53 p.m.
Vulnerabilities: cross-site scripting
Affected productsExternal IDs
vendor: cisco model: nexus

Trust: 5.0

Fetched: Feb. 17, 2023, 9:18 a.m., Published: Feb. 16, 2023, 8:42 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: draytek model: vigor
db: NVD ids: CVE-2022-46169
Related entries in the VARIoT vulnerabilities database: VAR-201505-0363, VAR-202002-1447, VAR-201705-3255, VAR-202006-1056, VAR-202206-0004

Trust: 5.75

Fetched: Feb. 17, 2023, 9:18 a.m., Published: Feb. 16, 2023, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: draytek model: vigor
vendor: palo model: networks
vendor: palo alto networks model: networks
db: NVD ids: CVE-2022-4257, CVE-2014-9727, CVE-2019-15107, CVE-2020-8515, CVE-2017-5173, CVE-2022-36267, CVE-2020-15415, CVE-2012-4869, CVE-2022-26134

Trust: 3.75

Fetched: Feb. 17, 2023, 9:18 a.m., Published: Feb. 16, 2023, 3:35 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: trend model: security
Related entries in the VARIoT vulnerabilities database: VAR-201505-0363, VAR-202002-1447, VAR-201705-3255, VAR-202006-1056, VAR-202206-0004

Trust: 5.25

Fetched: Feb. 17, 2023, 9:17 a.m., Published: Feb. 15, 2023, 6 a.m.
Vulnerabilities: remote command injection, command injection, arbitrary command execution...
Affected productsExternal IDs
vendor: draytek model: vigor
vendor: palo model: networks
vendor: palo model: firewall
vendor: palo alto networks model: networks
vendor: palo alto networks model: firewall
db: NVD ids: CVE-2022-4257, CVE-2014-9727, CVE-2019-15107, CVE-2020-8515, CVE-2017-5173, CVE-2022-36267, CVE-2020-15415, CVE-2012-4869, CVE-2022-26134
Related entries in the VARIoT vulnerabilities database: VAR-202302-0213

Trust: 5.5

Fetched: Feb. 17, 2023, 9:17 a.m., Published: Feb. 2, 2023, midnight
Vulnerabilities: path traversal, remote command injection, command injection...
Affected productsExternal IDs
vendor: cisco model: cgr1000
vendor: cisco model: catalyst
vendor: cisco model: access points
vendor: cisco model: ic3000
vendor: cisco model: routers
vendor: cisco model: industrial isrs
vendor: cisco model: series
vendor: cisco model: 4431
vendor: cisco model: wireless access point
vendor: cisco model: router
vendor: cisco model: ios xe
vendor: cisco model: ir510 wpan
db: NVD ids: CVE-2023-20076

Trust: 4.0

Fetched: Feb. 17, 2023, 9:16 a.m., Published: Feb. 15, 2023, 3:53 p.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: cisco model: nexus