VARIoT news about IoT security

Related entries in the VARIoT vulnerabilities database: VAR-201806-1164, VAR-201806-1163, VAR-201911-1328

Trust: 4.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Jan. 17, 2022, midnight
Vulnerabilities: sql injection, cross-site scripting, code execution...
Affected productsExternal IDs
vendor: essential model: phone
vendor: huawei model: huawei
vendor: huawei model: webui
vendor: trend model: security
vendor: axis model: axis
vendor: pfsense model: pfsense
vendor: zoho model: manageengine oputils
vendor: zoho model: manageengine applications manager
vendor: zoho model: manageengine opmanager
vendor: zoho model: manageengine netflow analyzer
vendor: zoho model: opmanager
vendor: zoho model: oputils
vendor: zoho model: manageengine servicedesk plus
vendor: google model: nexus
vendor: google model: android
vendor: google model: google chrome
vendor: google model: chrome
vendor: aruba model: instant
vendor: cisco model: cisco ios
vendor: cisco model: router
vendor: cisco model: nexus
vendor: cisco model: quad
vendor: cisco model: access points
vendor: cisco model: aireos
vendor: cisco model: routers
vendor: cisco model: technical support
vendor: cisco model: wireless lan controller
vendor: cisco model: wide area application services
vendor: cisco model: wireless lan controllers
vendor: cisco model: series
vendor: cisco model: wireless controller
vendor: cisco model: cisco routers
vendor: cisco model: spark
vendor: palo model: firewall
vendor: palo model: networks
vendor: jquery model: jquery
db: NVD ids: CVE-2019-8929, CVE-2019-7427, CVE-2018-12998, CVE-2018-12997, CVE-2019-7423, CVE-2018-10803, CVE-2020-11946, CVE-2019-8926, CVE-2019-12196, CVE-2020-12116, CVE-2021-20078, CVE-2021-3287, CVE-2021-41075, CVE-2019-8927, CVE-2019-17421, CVE-2018-19403, CVE-2019-7425, CVE-2019-7424, CVE-2020-10541, CVE-2017-11560, CVE-2019-8928, CVE-2019-7422, CVE-2019-7426, CVE-2008-0128, CVE-2021-44514, CVE-2019-8925

Trust: 4.0

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Sept. 2, 2021, 12:29 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2021-28139

Trust: 3.5

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Jan. 15, 2022, midnight
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: netgear model: netgear router
vendor: netgear model: netgear router firmware
vendor: netgear model: gs750e
vendor: netgear model: router
vendor: netgear model: gs752tpp
vendor: netgear model: gs728tppv2

Trust: 4.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: serve model: serve
vendor: trend model: security

Trust: 5.5

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Jan. 3, 2022, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: cisco systems model: ucs manager
vendor: cisco systems model: cisco systems
vendor: cisco systems model: cisco ucs manager
vendor: cisco systems model: unified_computing_system
vendor: cisco model: ucs manager
vendor: cisco model: cisco systems
vendor: cisco model: cisco ucs manager
vendor: cisco model: unified_computing_system
db: NVD ids: CVE-2021-1592
Related entries in the VARIoT vulnerabilities database: VAR-201505-0274

Trust: 6.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: command execution, command injection, buffer overflow...
Affected productsExternal IDs
vendor: realtek model: realtek sdk
vendor: d-link model: eyeon baby monitor
vendor: d-link model: dcs-825l
vendor: d-link model: router
vendor: buffalo model: wsr-300hp
vendor: buffalo model: router
vendor: trend micro model: security
vendor: trend micro model: home network security
vendor: dahua model: ptz camera
vendor: dahua model: camera
vendor: dahua model: ip camera
vendor: belkin model: router
vendor: trend model: security
vendor: trend model: home network security
db: NVD ids: CVE-2014-8361
Related entries in the VARIoT vulnerabilities database: VAR-202012-0245, VAR-202012-0125

Trust: 3.5

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: siemens model: sentron pac4200
vendor: siemens model: sentron pac3200
vendor: siemens model: modbus tcp
db: SIEMENS ids: SSA-541018
db: NVD ids: CVE-2020-17437, CVE-2020-13987
db: ICS CERT ids: ICSA-21-068-06
db: US CERT ids: ICSA-21-068-06
Related entries in the VARIoT vulnerabilities database: VAR-202109-0622

Trust: 5.5

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Jan. 15, 2022, midnight
Vulnerabilities: code execution, authentication bypass
Affected productsExternal IDs
vendor: cisco model: prime infrastructure
vendor: cisco model: firepower
vendor: cisco model: identity services engine
vendor: cisco model: device manager
vendor: cisco model: routers
vendor: cisco model: prime collaboration provisioning
vendor: cisco model: nexus
vendor: cisco model: prime collaboration
db: NVD ids: CVE-2021-34746

Trust: 4.75

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Aug. 18, 2021, 3:48 p.m.
Vulnerabilities: improper access control, code execution, access control flaw
Affected productsExternal IDs
db: NVD ids: CVE-2021-28372, CVE-2021-32934

Trust: 3.5

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Aug. 20, 2021, midnight
Vulnerabilities: data injection, brute force attack, injection attack
Affected productsExternal IDs
Related entries in the VARIoT vulnerabilities database: VAR-202104-0768

Trust: 5.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Aug. 12, 2021, 2:46 a.m.
Vulnerabilities: authentication bypass, path traversal
Affected productsExternal IDs
vendor: buffalo model: router
vendor: serve model: serve
db: NVD ids: CVE-2021-20090

Trust: 4.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Nov. 15, 2021, midnight
Vulnerabilities: use after free, denial of service, code execution...
Affected productsExternal IDs
vendor: motorola model: motorola
vendor: motorola model: android
vendor: samsung model: note
vendor: samsung model: notes
vendor: samsung model: samsung
vendor: samsung model: mobile
vendor: huawei model: huawei
vendor: broadcom model: broadcom
vendor: nokia model: nokia
vendor: google model: android
vendor: google model: pixel
db: NVD ids: CVE-2021-30284, CVE-2021-0928, CVE-2021-1924, CVE-2021-0927, CVE-2021-0650, CVE-2021-0672, CVE-2021-1975, CVE-2021-1048, CVE-2021-1982, CVE-2021-1979, CVE-2021-0925, CVE-2021-30255, CVE-2021-1973, CVE-2021-0649, CVE-2021-0932, CVE-2021-0918, CVE-2021-0434, CVE-2021-0920, CVE-2021-0931, CVE-2021-0930, CVE-2021-0919, CVE-2021-1981, CVE-2021-0653, CVE-2021-1921, CVE-2021-0889, CVE-2021-30254

Trust: 3.0

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Aug. 17, 2021, 9:06 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs

Trust: 4.0

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Sept. 2, 2021, 4 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2021-28139
Related entries in the VARIoT vulnerabilities database: VAR-201505-0274

Trust: 6.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: command execution, command injection, buffer overflow...
Affected productsExternal IDs
vendor: realtek model: realtek sdk
vendor: d-link model: eyeon baby monitor
vendor: d-link model: dcs-825l
vendor: d-link model: router
vendor: buffalo model: wsr-300hp
vendor: buffalo model: router
vendor: trend micro model: security
vendor: trend micro model: home network security
vendor: dahua model: ptz camera
vendor: dahua model: camera
vendor: dahua model: ip camera
vendor: belkin model: router
vendor: trend model: security
vendor: trend model: home network security
db: NVD ids: CVE-2014-8361
Related entries in the VARIoT vulnerabilities database: VAR-202108-2056

Trust: 3.75

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: macos
db: NVD ids: CVE-2021-30892

Trust: 3.5

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Oct. 6, 2021, 9 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: medtronic model: paradigm
vendor: medtronic model: minimed 508
vendor: check point model: check point

Trust: 3.0

Fetched: Nov. 4, 2021, 1:02 p.m., Published: June 2, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: wireshark model: wireshark

Trust: 3.25

Fetched: Nov. 4, 2021, 1:02 p.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: wso2 model: enterprise mobility manager
Related entries in the VARIoT vulnerabilities database: VAR-202109-0622

Trust: 4.5

Fetched: Nov. 4, 2021, 1:02 p.m., Published: Jan. 3, 2022, midnight
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: cisco systems model: cisco systems
vendor: cisco model: cisco systems
db: NVD ids: CVE-2021-34746