VARIoT news about IoT security

Trust: 4.25

Fetched: Jan. 5, 2024, 9:19 a.m., Published: Dec. 28, 2023, 9:04 p.m.
Vulnerabilities: privilege escalation, code execution, integer overflow
Affected productsExternal IDs
vendor: apple model: safari
vendor: apple model: iphone
db: NVD ids: CVE-2023-32434, CVE-2023-32435, CVE-2023-41990, CVE-2023-38606
Related entries in the VARIoT vulnerabilities database: VAR-202309-2499, VAR-202309-1995, VAR-202401-0651, VAR-202401-0433, VAR-202401-0655, VAR-202401-1328

Trust: 4.25

Fetched: Jan. 5, 2024, 9:18 a.m., Published: Jan. 5, 2024, midnight
Vulnerabilities: denial of service, information disclosure, code execution
Affected productsExternal IDs
vendor: huawei model: huawei
vendor: samsung model: mobile
vendor: samsung model: notes
vendor: google model: pixel
vendor: google model: android
vendor: motorola model: android
vendor: motorola model: motorola
db: NVD ids: CVE-2023-48350, CVE-2023-33032, CVE-2023-48349, CVE-2023-48342, CVE-2023-33109, CVE-2023-33025, CVE-2023-33112, CVE-2023-48340, CVE-2023-48351, CVE-2024-0016, CVE-2023-21245, CVE-2023-48344, CVE-2023-28559, CVE-2023-28564, CVE-2023-21651, CVE-2023-48348, CVE-2023-28565, CVE-2023-33014, CVE-2023-28558, CVE-2024-0018, CVE-2023-33044, CVE-2023-43511, CVE-2023-48341, CVE-2023-28548, CVE-2023-33040, CVE-2023-33062, CVE-2023-33033, CVE-2023-21165, CVE-2024-0017, CVE-2024-0015, CVE-2023-33030, CVE-2023-5427, CVE-2023-32874, CVE-2023-32872, CVE-2023-28557, CVE-2023-48352, CVE-2023-28567, CVE-2024-0021, CVE-2022-33275, CVE-2023-4295, CVE-2023-28560, CVE-2023-48343, CVE-2023-33036, CVE-2023-33037, CVE-2023-33043, CVE-2023-28544, CVE-2024-0020, CVE-2024-0019, CVE-2024-0023, CVE-2023-40085

Trust: 5.25

Fetched: Jan. 5, 2024, 9:17 a.m., Published: Jan. 3, 2024, midnight
Vulnerabilities: timing attack, information disclosure, denial of service...
Affected productsExternal IDs
vendor: cisco model: cisco nexus 9000 series
vendor: cisco model: nexus 9000 series
vendor: cisco model: series
vendor: cisco model: nexus 9000
vendor: cisco model: nexus
vendor: infineon model: rsa library
vendor: infineon model: trusted platform
vendor: citrix model: gateway
vendor: dell model: latitude
vendor: dell model: bios
vendor: google model: chrome os
vendor: google model: chrome
vendor: google model: nexus
db: NVD ids: CVE-2020-5851, CVE-2023-30633, CVE-2021-42299, CVE-2020-12946, CVE-2022-1053, CVE-2022-23645, CVE-2022-26355, CVE-2020-12926, CVE-2021-3505, CVE-2023-43635, CVE-2023-22745, CVE-2023-1018, CVE-2017-15361, CVE-2021-32015, CVE-2021-1656, CVE-2017-16837, CVE-2011-1160, CVE-2020-8918, CVE-2014-8669, CVE-2023-1017, CVE-2018-6686, CVE-2019-16863, CVE-2010-4121, CVE-2011-1162, CVE-2019-1589, CVE-2020-26933, CVE-2021-3623, CVE-2007-5559, CVE-2008-5686, CVE-2019-6322, CVE-2018-6622, CVE-2017-10606, CVE-2023-29360, CVE-2023-43632, CVE-2014-0881, CVE-2023-3674, CVE-2022-2977, CVE-2019-6321, CVE-2021-38576, CVE-2013-3582

Trust: 4.5

Fetched: Jan. 5, 2024, 9:11 a.m., Published: Jan. 4, 2024, 7:02 a.m.
Vulnerabilities: injection attack, code execution, remote command injection...
Affected productsExternal IDs
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: adaptive security appliance
vendor: cisco model: router
vendor: cisco model: sd-wan vmanage
vendor: cisco model: sd-wan
vendor: cisco model: series
vendor: cisco systems model: cisco adaptive security appliance
vendor: cisco systems model: adaptive security appliance
vendor: cisco systems model: router
vendor: cisco systems model: sd-wan vmanage
vendor: cisco systems model: sd-wan
vendor: cisco systems model: series

Trust: 5.0

Fetched: Jan. 5, 2024, 9:10 a.m., Published: Jan. 4, 2024, 9:37 p.m.
Vulnerabilities: sql injection, code execution
Affected productsExternal IDs
vendor: mobileiron model: sentry
db: NVD ids: CVE-2023-39366, CVE-2023-35078, CVE-2023-38035, CVE-2023-35081

Trust: 5.5

Fetched: Jan. 5, 2024, 9:09 a.m., Published: Dec. 31, 2023, noon
Vulnerabilities: buffer overflow, denial of service, code execution
Affected productsExternal IDs
vendor: apple model: tvos
vendor: apple model: iphone
vendor: apple model: webkit
vendor: apple model: safari
vendor: apple model: macos
vendor: apple model: watchos
vendor: google model: chrome
vendor: google model: pixel
vendor: google model: android
db: NVD ids: CVE-2023-7024, CVE-2023-40078, CVE-2023-4291, CVE-2023-42890, CVE-2023-40094, CVE-2023-42898, CVE-2023-6702, CVE-2023-42940, CVE-2023-42899, CVE-2023-40088

Trust: 4.75

Fetched: Jan. 3, 2024, 9:57 a.m., Published: Dec. 12, 2023, 11:38 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: apple model: macos
vendor: apple model: safari
vendor: apple model: tvos
vendor: apple model: watchos
vendor: apple model: webkit
db: NVD ids: CVE-2023-42883, CVE-2023-42917, CVE-2023-45866, CVE-2023-42890, CVE-2023-42916

Trust: 3.25

Fetched: Jan. 3, 2024, 9:54 a.m., Published: Jan. 3, 2024, 5:15 a.m.
Vulnerabilities: cross-site scripting
Affected productsExternal IDs
db: NVD ids: CVE-2023-7027
Related entries in the VARIoT vulnerabilities database: VAR-201603-0281

Trust: 5.75

Fetched: Jan. 3, 2024, 9:49 a.m., Published: Dec. 20, 2023, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: cisco model: cisco ios
vendor: cisco model: nx-os software
vendor: cisco model: nx-os
vendor: cisco model: nx-os 4.1
db: NVD ids: CVE-2016-1351

Trust: 3.75

Fetched: Jan. 3, 2024, 9:49 a.m., Published: Jan. 2, 2024, midnight
Vulnerabilities: authentication vulnerability, cross-site scripting, resource exhaustion...
Affected productsExternal IDs
db: NVD ids: CVE-2023-44361, CVE-2023-4137, CVE-2023-5360, CVE-2022-26833, CVE-2023-38039, CVE-2023-40056, CVE-2021-3129

Trust: 4.5

Fetched: Jan. 3, 2024, 9:46 a.m., Published: Dec. 22, 2023, 5:23 a.m.
Vulnerabilities: injection attack, authentication error, access control vulnerability...
Affected productsExternal IDs
vendor: apple model: icloud
db: NVD ids: CVE-2023-34362, CVE-2021-26857, CVE-2021-27065, CVE-2021-26855, CVE-2021-26858

Trust: 4.25

Fetched: Jan. 3, 2024, 9:46 a.m., Published: Dec. 19, 2023, midnight
Vulnerabilities: improper access control
Affected productsExternal IDs
db: NVD ids: CVE-2021-0187

Trust: 5.25

Fetched: Jan. 3, 2024, 9:46 a.m., Published: Dec. 28, 2023, midnight
Vulnerabilities: input validation vulnerability
Affected productsExternal IDs
vendor: dell model: bios

Trust: 4.25

Fetched: Jan. 3, 2024, 9:45 a.m., Published: Dec. 19, 2023, midnight
Vulnerabilities: improper access control
Affected productsExternal IDs
db: NVD ids: CVE-2022-26343
Related entries in the VARIoT vulnerabilities database: VAR-202302-0195

Trust: 4.75

Fetched: Jan. 3, 2024, 9:45 a.m., Published: Dec. 19, 2023, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: siemens model: scalance
vendor: siemens model: scalance w1750d
vendor: siemens model: w1750d
db: NVD ids: CVE-2022-4450

Trust: 4.0

Fetched: Jan. 3, 2024, 9:38 a.m., Published: Dec. 21, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: cups model: cups
db: NVD ids: CVE-2020-0556, CVE-2023-45866

Trust: 3.75

Fetched: Jan. 3, 2024, 9:32 a.m., Published: Jan. 3, 2024, midnight
Vulnerabilities: buffer overflow, denial of service
Affected productsExternal IDs
db: NVD ids: CVE-2012-5962, CVE-2012-5958, CVE-2021-29462, CVE-2016-8863, CVE-2012-5964, CVE-2020-13848, CVE-2012-5965, CVE-2012-5960, CVE-2012-5959, CVE-2012-5963, CVE-2012-5961, CVE-2016-6255

Trust: 3.25

Fetched: Jan. 3, 2024, 9:31 a.m., Published: Jan. 3, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2023-38186
Related entries in the VARIoT vulnerabilities database: VAR-202401-0655

Trust: 5.5

Fetched: Jan. 3, 2024, 9:29 a.m., Published: Jan. 2, 2024, 10:11 p.m.
Vulnerabilities: memory corruption, integer overflow, buffer overflow...
Affected productsExternal IDs
vendor: motorola model: motorola
vendor: motorola model: android
vendor: samsung model: samsung galaxy
vendor: samsung model: mobile
vendor: samsung model: galaxy
db: NVD ids: CVE-2023-33036, CVE-2023-33030, CVE-2023-33025, CVE-2023-33032

Trust: 3.25

Fetched: Jan. 3, 2024, 9:29 a.m., Published: Jan. 3, 2024, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs