VARIoT news about IoT security

Related entries in the VARIoT vulnerabilities database: VAR-201910-0546, VAR-201910-0547, VAR-201803-2171, VAR-201808-0384

Trust: 5.25

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 9, 2021, midnight
Vulnerabilities: code execution, weak password, buffer overflow
Affected productsExternal IDs
vendor: mikrotik model: mikrotik
vendor: mikrotik model: winbox
vendor: mikrotik model: router
vendor: mikrotik model: routers
vendor: mikrotik model: routeros
vendor: mikrotik model: mikrotik routers
db: NVD ids: CVE-2019-3977, cve-2018-14847, CVE-2019-3978, CVE-2018-7445, CVE-2018-14847
db: POSIVITIVE TECHNOLOGY ids: ID:10

Trust: 3.75

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 15, 2021, 9:42 p.m.
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: cve-2021-44228
db: VMWARE ids: VMSA-2021-0028
Related entries in the VARIoT vulnerabilities database: VAR-202112-1782, VAR-202112-0566, VAR-202112-0562

Trust: 3.75

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 14, 2021, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2021-45105, CVE-2021-44228, CVE-2021-45046

Trust: 4.75

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Nov. 30, 2021, 12:32 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: samsung model: note
vendor: samsung model: android phone
vendor: samsung model: samsung
vendor: vivo model: vivo
vendor: google model: chrome
vendor: google model: android
vendor: check point model: check point
db: NVD ids: CVE-2021-0662, CVE-2021-0661, CVE-2021-0663

Trust: 3.0

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 14, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: icloud
Related entries in the VARIoT vulnerabilities database: VAR-202112-1782, VAR-202112-0566, VAR-202112-2011, VAR-202112-0562, VAR-201704-1589, VAR-201912-0889

Trust: 5.25

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 10, 2021, 9 p.m.
Vulnerabilities: denial of service, code execution, code injection
Affected productsExternal IDs
vendor: canary model: canary
vendor: palo model: networks
vendor: palo model: firewall
vendor: palo model: palo alto networks
vendor: palo alto networks model: networks
vendor: palo alto networks model: firewall
vendor: palo alto networks model: palo alto networks
vendor: snort model: snort
db: NVD ids: CVE-2021-45105, CVE-2021-44228, CVE-2021-44832, CVE-2021-45046, CVE-2017-5645, CVE-2019-17571

Trust: 3.0

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: android

Trust: 4.75

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: raspberry pi model: 3
Related entries in the VARIoT vulnerabilities database: VAR-202003-1707

Trust: 4.25

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: denial of service, default credentials
Affected productsExternal IDs
vendor: serve model: serve
vendor: trend micro model: home network security
vendor: trend micro model: security
vendor: sonos model: sonos
vendor: trend model: home network security
vendor: trend model: security
db: NVD ids: CVE-2020-9054

Trust: 3.5

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: baxter model: prismax
vendor: baxter model: prismaflex
vendor: baxter model: spectrum infusion system
vendor: baxter model: wireless battery module

Trust: 4.75

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: request forgery, code execution, cross-site request forgery...
Affected productsExternal IDs
vendor: moxa model: nport 5600 series
vendor: moxa model: nport 5200a series
vendor: moxa model: nport 5600-dt/dtl
vendor: moxa model: nport 5400 series
vendor: moxa model: nport p5150a
vendor: moxa model: nport
vendor: moxa model: nport 5200a
vendor: moxa model: nport 5100a series
vendor: moxa model: nport 5100a
vendor: moxa model: nport 5200 series
vendor: moxa model: nport p5150a series
vendor: moxa model: nport 5x50ai-m12
vendor: moxa model: moxa
vendor: moxa model: nport 5100 series
db: ICS CERT ids: ICSA-16-336-02
db: ICS CERT ALERT ids: ICS-ALERT-10-301-01, ICS-ALERT-16-099-01B, ICS-ALERT-16-099-01A, ICS-ALERT-16-099-01
db: US CERT ids: ICSA-16-336-02

Trust: 4.75

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: cve-2020-15858

Trust: 4.75

Fetched: Dec. 16, 2021, 3:47 p.m., Published: Jan. 1, 2022, midnight
Vulnerabilities: code execution, information leakage
Affected productsExternal IDs
db: NVD ids: CVE-2021-27408

Trust: 4.0

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: trend model: security

Trust: 5.25

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: memory corruption, denial of service, improper memory handling...
Affected productsExternal IDs
vendor: cisco model: hsrp
vendor: cisco model: nx-os
vendor: cisco model: ios software
vendor: cisco model: cisco ios
vendor: cisco model: series switches
vendor: cisco model: routers
vendor: cisco model: 4451-x
vendor: cisco model: integrated services router
vendor: cisco model: integrated services routers
vendor: cisco model: catalyst 2960-l series switches
vendor: cisco model: catalyst 6500 series
vendor: cisco model: ios xe
vendor: cisco model: cisco iox
vendor: cisco model: ios xr
vendor: cisco model: iox application
vendor: cisco model: nx-os software
vendor: cisco model: ios xr software
vendor: cisco model: catalyst cdb-8p switches
vendor: cisco model: catalyst
vendor: cisco model: catalyst 6500
vendor: cisco model: cisco nx-os
vendor: cisco model: isr g2
vendor: cisco model: isr4451
vendor: cisco model: isr4451-x
vendor: cisco model: ios xe software
vendor: cisco model: cisco iox application
vendor: cisco model: 4451-x integrated services router
vendor: cisco model: cisco ios xe
vendor: cisco model: industrial integrated services routers
vendor: cisco model: cisco ios xr
vendor: cisco model: series
vendor: cisco model: router
db: NVD ids: CVE-2019-12649, CVE-2018-15369, CVE-2019-1748, CVE-2021-34705, CVE-2018-0473, CVE-2019-1756, CVE-2018-15373, CVE-2019-16009, CVE-2018-15377, CVE-2019-12655, CVE-2021-34699, CVE-2019-12650, CVE-2018-0485, CVE-2018-0475, CVE-2019-12670, CVE-2020-3201, CVE-2019-1758, CVE-2019-1752, CVE-2020-3230, CVE-2020-3226, CVE-2018-0484, CVE-2020-3200, CVE-2019-1757, CVE-2019-12668, CVE-2019-1739, CVE-2018-15376, CVE-2021-1385, CVE-2021-1392, CVE-2019-12656, CVE-2019-12672, CVE-2019-12665, CVE-2019-1762, CVE-2019-1746, CVE-2020-3476, CVE-2019-1737, CVE-2018-0466, CVE-2021-1377, CVE-2019-1738, CVE-2009-1234, CVE-2021-1391, CVE-2019-1761, CVE-2020-3204, CVE-2018-15375, CVE-2019-12651, CVE-2019-1740, CVE-2020-3228, CVE-2020-3231, CVE-2019-1751, CVE-2020-3225, CVE-2020-3217, CVE-2019-1747
Related entries in the VARIoT vulnerabilities database: VAR-202112-0566

Trust: 3.5

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: code execution, denial of service, information leak
Affected productsExternal IDs
db: NVD ids: cve-2021-44228, CVE-2021-44228
Related entries in the VARIoT vulnerabilities database: VAR-202003-1707

Trust: 3.75

Fetched: Dec. 16, 2021, 3:47 p.m., Published: Jan. 5, 2022, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: zyxel model: usg310
vendor: zyxel model: usg60
vendor: zyxel model: vpn300
vendor: zyxel model: zywall1100
vendor: zyxel model: usg60w_firmware
vendor: zyxel model: usg60w
vendor: zyxel model: vpn1000
vendor: zyxel model: nas542_firmware
vendor: zyxel model: usg20-vpn_firmware
vendor: zyxel model: vpn100_firmware
vendor: zyxel model: nas520
vendor: zyxel model: vpn100
vendor: zyxel model: usg20w-vpn
vendor: zyxel model: usg20w-vpn_firmware
vendor: zyxel model: zywall1100_firmware
vendor: zyxel model: atp100_firmware
vendor: zyxel model: usg110_firmware
vendor: zyxel model: zywall110_firmware
vendor: zyxel model: usg310_firmware
vendor: zyxel model: vpn1000_firmware
vendor: zyxel model: usg40w_firmware
vendor: zyxel model: zywall310
vendor: zyxel model: vpn300_firmware
vendor: zyxel model: usg1100_firmware
vendor: zyxel model: nas542
vendor: zyxel model: vpn50
vendor: zyxel model: vpn50_firmware
vendor: zyxel model: nas326_firmware
vendor: zyxel model: usg1900
vendor: zyxel model: usg210_firmware
vendor: zyxel model: usg1100
vendor: zyxel model: atp500_firmware
vendor: zyxel model: atp100
vendor: zyxel model: nas326
vendor: zyxel model: usg60_firmware
vendor: zyxel model: zywall110
vendor: zyxel model: atp200_firmware
vendor: zyxel model: zywall310_firmware
vendor: zyxel model: usg1900_firmware
vendor: zyxel model: nas520_firmware
vendor: zyxel model: usg210
vendor: zyxel model: usg20-vpn
vendor: zyxel model: usg40
vendor: zyxel model: usg2200_firmware
vendor: zyxel model: usg2200
vendor: zyxel model: usg40_firmware
vendor: zyxel model: atp500
vendor: zyxel model: nas540_firmware
vendor: zyxel model: usg110
vendor: zyxel model: atp200
vendor: zyxel model: atp800_firmware
vendor: zyxel model: nas540
vendor: zyxel model: atp800
vendor: zyxel model: usg40w
db: NVD ids: CVE-2020-9054
Related entries in the VARIoT vulnerabilities database: VAR-202004-1957

Trust: 3.25

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: cve-2020-9770, CVE-2020-9770

Trust: 3.5

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: denial of service, default password
Affected productsExternal IDs
Related entries in the VARIoT vulnerabilities database: VAR-201906-1020

Trust: 4.0

Fetched: Dec. 16, 2021, 3:47 p.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: medtronic model: paradigm
db: NVD ids: CVE-2019-10964