VARIoT news about IoT security

Trust: 5.25

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Oct. 27, 2021, midnight
Vulnerabilities: file upload vulnerability, information disclosure, buffer overflow...
Affected productsExternal IDs
vendor: trend model: security
vendor: delta model: diaenergie
vendor: fatek model: automation winproladder
vendor: fatek model: winproladder
vendor: centreon model: centreon
vendor: trend micro model: security
vendor: siemens model: solid edge viewer
vendor: siemens model: solid edge
vendor: fatek automation model: automation winproladder
vendor: fatek automation model: winproladder
vendor: tippingpoint model: tippingpoint
vendor: advantech model: webaccess
vendor: advantech model: advantech webaccess
vendor: delta industrial automation model: diaenergie
db: NVD ids: CVE-2021-37558, CVE-2021-34848, CVE-2021-26085, CVE-2021-31813, CVE-2021-24275, CVE-2021-32955

Trust: 3.5

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Dec. 17, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: freeipa model: freeipa
vendor: axis model: axis
vendor: google model: home
vendor: opensc model: opensc
vendor: mageia model: mageia
db: NVD ids: cve-2021-42574

Trust: 3.5

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Dec. 7, 2021, 8:32 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: pixel
vendor: google model: android
db: NVD ids: CVE-2021-1048
Related entries in the VARIoT vulnerabilities database: VAR-202111-1435

Trust: 5.75

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Jan. 5, 2022, midnight
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: huawei model: cloudengine 7800
vendor: huawei model: huawei
vendor: huawei model: cloudengine 5800
vendor: huawei model: cloudengine 12800
vendor: huawei model: cloudengine 6800
vendor: huawei model: cloudengine
db: NVD ids: CVE-2021-39976
Related entries in the VARIoT vulnerabilities database: VAR-202108-1374

Trust: 6.0

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Nov. 11, 2021, midnight
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: apple model: macos
db: NVD ids: CVE-2021-30869

Trust: 4.25

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Oct. 16, 2021, midnight
Vulnerabilities: denial of service, code execution, information disclosure...
Affected productsExternal IDs
vendor: citrix model: licensing
vendor: citrix model: hypervisor

Trust: 4.0

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Nov. 12, 2021, 11:58 a.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: serve model: serve
Related entries in the VARIoT vulnerabilities database: VAR-202108-2057

Trust: 5.5

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Oct. 28, 2021, 4:30 p.m.
Vulnerabilities: memory corruption, integer overflow
Affected productsExternal IDs
vendor: roku model: roku
vendor: apple model: tvos
vendor: apple model: apple tv
vendor: apple model: watch
db: NVD ids: CVE-2021-30883
Related entries in the VARIoT vulnerabilities database: VAR-202108-2056

Trust: 4.0

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Oct. 29, 2021, 1:31 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: macos
db: NVD ids: CVE-2021-30892

Trust: 3.75

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Oct. 29, 2021, 8:42 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: chrome
vendor: google model: google chrome
vendor: node.js model: node.js
db: NVD ids: CVE-2021-38000, CVE-2021-38001, CVE-2021-38002, CVE-2021-38003

Trust: 3.75

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Oct. 26, 2021, 1:03 p.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
db: NVD ids: CVE-2021-21284

Trust: 3.5

Fetched: Nov. 22, 2021, 8:12 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: iphone
vendor: apple model: macos
db: NVD ids: cve-2021-30858

Trust: 4.5

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Nov. 10, 2021, 5 p.m.
Vulnerabilities: os command injection, command injection
Affected productsExternal IDs
vendor: palo model: firewall
vendor: palo model: palo alto networks
vendor: palo model: pan-os
vendor: palo model: networks
vendor: paloaltonetworks model: firewall
vendor: paloaltonetworks model: palo alto networks
vendor: paloaltonetworks model: pan-os
vendor: paloaltonetworks model: networks
vendor: palo alto networks model: firewall
vendor: palo alto networks model: palo alto networks
vendor: palo alto networks model: pan-os
vendor: palo alto networks model: networks
db: NVD ids: CVE-2021-3059
Related entries in the VARIoT vulnerabilities database: VAR-202108-1048

Trust: 4.25

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Nov. 18, 2021, 9:29 p.m.
Vulnerabilities: command execution, code execution, request forgery...
Affected productsExternal IDs
vendor: wireshark model: wireshark
vendor: serve model: serve
db: NVD ids: CVE-2021-27406, CVE-2021-33527, CVE-2021-31338, CVE-2020-14498, CVE-2021-33526
Related entries in the VARIoT vulnerabilities database: VAR-202111-0789, VAR-202111-0473, VAR-202111-0697, VAR-202111-0660

Trust: 3.5

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Nov. 9, 2021, midnight
Vulnerabilities: security feature bypass, cross-site scripting, cross-site request forgery...
Affected productsExternal IDs
db: NVD ids: CVE-2021-42283, CVE-2021-41378, CVE-2021-42300, CVE-2021-41376, CVE-2021-41367, CVE-2021-41379, CVE-2021-42285, CVE-2021-41374, CVE-2021-42323, CVE-2021-41368, CVE-2021-42277, CVE-2021-41373, CVE-2021-42287, CVE-2021-42278, CVE-2021-42291, CVE-2021-42301, CVE-2021-26443, CVE-2021-42319, CVE-2021-42292, CVE-2021-26444, CVE-2021-42274, CVE-2021-41370, CVE-2021-42275, CVE-2021-43208, CVE-2021-43209, CVE-2021-42316, CVE-2021-41366, CVE-2021-42286, CVE-2021-42282, CVE-2021-42296, CVE-2021-41349, CVE-2021-41377, CVE-2021-42304, CVE-2021-42322, CVE-2021-42276, CVE-2021-42288, CVE-2021-41351, CVE-2021-42279, CVE-2021-42305, CVE-2021-42321, CVE-2021-42302, CVE-2021-42298, CVE-2021-38665, CVE-2021-41375, CVE-2021-40442, CVE-2021-41372, CVE-2021-42303, CVE-2021-38666, CVE-2021-3711, CVE-2021-41356, CVE-2021-42284, CVE-2021-41371, CVE-2021-42280, CVE-2021-36957, CVE-2021-38631

Trust: 3.5

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Nov. 9, 2021, 2 p.m.
Vulnerabilities: denial of service, information leak, code execution...
Affected productsExternal IDs
db: NVD ids: CVE-2021-42386, CVE-2021-42376, CVE-2021-42373, CVE-2021-42374, CVE-2021-42377, CVE-2021-42375, CVE-2021-42378
Related entries in the VARIoT vulnerabilities database: VAR-202108-1374

Trust: 5.75

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Nov. 12, 2021, 6:28 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: apple model: webkit
vendor: apple model: macos
vendor: apple model: safari
db: NVD ids: CVE-2021-30869

Trust: 3.75

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Nov. 9, 2021, 8:30 p.m.
Vulnerabilities: feature bypass, denial of service, information disclosure...
Affected productsExternal IDs

Trust: 3.5

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Nov. 6, 2021, 8:47 a.m.
Vulnerabilities: denial of service, code execution
Affected productsExternal IDs
vendor: samsung model: samsung

Trust: 3.25

Fetched: Nov. 22, 2021, 8:12 a.m., Published: Dec. 30, 2021, 8:21 p.m.
Vulnerabilities: remote command injection, privilege escalation, request forgery...
Affected productsExternal IDs
vendor: zoom model: zoom
vendor: zoom model: client
vendor: zoom model: zoom client
vendor: blackberry model: blackberry
vendor: blackberry model: link
vendor: ringcentral model: ringcentral
vendor: google model: chrome
vendor: google model: chrome os
vendor: google model: android