VARIoT news about IoT security

Trust: 4.75

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Aug. 17, 2021, midnight
Vulnerabilities: device impersonation
Affected productsExternal IDs
db: NVD ids: CVE-2021-28372, CVE-2021-32934

Trust: 4.5

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: qemu model: qemu
vendor: xiongmai model: ip cameras
Related entries in the VARIoT vulnerabilities database: VAR-202108-2053, VAR-202108-2054, VAR-202108-2057

Trust: 3.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Oct. 14, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2021-30896, CVE-2021-30895, CVE-2021-30883
db: APPLE ids: APPLE-SA-2021-10-11-1
Related entries in the VARIoT vulnerabilities database: VAR-202111-0609, VAR-202108-1005, VAR-202111-0579

Trust: 3.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2021-1048, CVE-2021-1975, CVE-2021-0918, CVE-2021-34484, CVE-2021-0889, CVE-2021-1924, CVE-2021-0930

Trust: 4.75

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Aug. 31, 2021, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2021-34145, CVE-2021-34144, CVE-2021-31611, CVE-2021-34146, CVE-2021-31612, CVE-2021-28136, CVE-2021-28139, CVE-2021-34148, CVE-2021-31610, CVE-2021-28155, CVE-2021-31785, CVE-2021-34150, CVE-2021-34143, CVE-2021-31717, CVE-2021-31613, CVE-2021-34149, CVE-2021-31609, CVE-2021-34147, CVE-2021-28135, CVE-2021-31786
Related entries in the VARIoT vulnerabilities database: VAR-201501-0737

Trust: 5.75

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Jan. 2, 2022, midnight
Vulnerabilities: cross-site scripting, command injection, buffer overflow
Affected productsExternal IDs
vendor: moxa model: moxa
vendor: moxa model: wac-1001
db: NVD ids: CVE-2021-39278, CVE-2021-39279, CVE-2015-0235

Trust: 4.0

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Aug. 18, 2021, 9:54 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2021-28372

Trust: 3.0

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Sept. 13, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2021-40824, CVE-2021-40823

Trust: 3.0

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: code execution
Affected productsExternal IDs

Trust: 4.75

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Aug. 31, 2021, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2021-34145, CVE-2021-34144, CVE-2021-31611, CVE-2021-34146, CVE-2021-31612, CVE-2021-28136, CVE-2021-28139, CVE-2021-34148, CVE-2021-31610, CVE-2021-28155, CVE-2021-31785, CVE-2021-34150, CVE-2021-34143, CVE-2021-31717, CVE-2021-31613, CVE-2021-34149, CVE-2021-31609, CVE-2021-34147, CVE-2021-28135, CVE-2021-31786
Related entries in the VARIoT vulnerabilities database: VAR-202108-0317

Trust: 5.75

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: improper access control
Affected productsExternal IDs
vendor: cisco model: nexus_92300yc
vendor: cisco model: nexus 9000 series
vendor: cisco model: series
vendor: cisco model: nexus_9000
vendor: cisco model: nexus
vendor: cisco model: nexus_92160yc-x
vendor: cisco model: nexus_92304qc
vendor: cisco model: nx-os
vendor: cisco model: cisco nexus 9000 series
vendor: cisco model: cisco systems
vendor: cisco model: nexus 9000
vendor: cisco model: nexus_9000v
vendor: cisco systems model: nexus_92300yc
vendor: cisco systems model: nexus 9000 series
vendor: cisco systems model: series
vendor: cisco systems model: nexus_9000
vendor: cisco systems model: nexus
vendor: cisco systems model: nexus_92160yc-x
vendor: cisco systems model: nexus_92304qc
vendor: cisco systems model: nx-os
vendor: cisco systems model: cisco nexus 9000 series
vendor: cisco systems model: cisco systems
vendor: cisco systems model: nexus 9000
vendor: cisco systems model: nexus_9000v
db: NVD ids: CVE-2021-1583

Trust: 4.5

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: command injection, memory corruption, denial of service
Affected productsExternal IDs
vendor: cisco model: iox application
vendor: cisco model: cisco iox
vendor: cisco model: cisco iox application
vendor: cisco model: series
vendor: cisco model: cisco ios xe
vendor: cisco model: ios xe software
vendor: cisco model: series switches
vendor: cisco model: ios xe
vendor: cisco model: ios software
vendor: cisco model: catalyst
vendor: cisco model: cisco ios
db: NVD ids: CVE-2021-1446, CVE-2021-34699, CVE-2021-1377, CVE-2021-1391, CVE-2021-1435, CVE-2021-1619, CVE-2021-1442, CVE-2021-1390, CVE-2009-1234, CVE-2021-1384, CVE-2021-1403, CVE-2021-1453, CVE-2021-34705, CVE-2021-1376, CVE-2021-1352

Trust: 3.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Jan. 3, 2022, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: amazon model: echo show
vendor: comcast model: xfinity
vendor: comcast model: comcast xfinity
vendor: ring model: ring
vendor: google model: home
Related entries in the VARIoT vulnerabilities database: VAR-202108-1005

Trust: 3.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2021-28372, CVE-2021-34484

Trust: 4.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Oct. 10, 2021, 10:36 p.m.
Vulnerabilities: buffer overflow, use after free
Affected productsExternal IDs
vendor: google model: chrome
vendor: google model: google chrome
db: NVD ids: CVE-2021-37979, CVE-2021-37980, CVE-2021-37977, CVE-2021-37978

Trust: 3.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Jan. 5, 2022, 4:40 a.m.
Vulnerabilities: sql injection, cross-site scripting
Affected productsExternal IDs
vendor: aircrack-ng model: aircrack-ng
vendor: netbsd model: netbsd
vendor: tripwire model: ip360
vendor: wireshark model: wireshark

Trust: 3.75

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Aug. 16, 2021, 6:51 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: serve model: serve
vendor: asustek model: wireless routers

Trust: 3.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Nov. 3, 2021, midnight
Vulnerabilities: account lockout, address change vulnerability
Affected productsExternal IDs
vendor: cisco model: cisco routers
vendor: cisco model: routers
vendor: cisco model: technical support
vendor: cisco model: secure desktop

Trust: 4.0

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Aug. 23, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: trend model: security

Trust: 3.0

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Jan. 9, 2022, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: dell model: optiplex