VARIoT news about IoT security

Related entries in the VARIoT vulnerabilities database: VAR-202305-2099, VAR-202305-2096

Trust: 4.5

Fetched: May 12, 2023, 9:15 a.m., Published: March 10, 2023, midnight
Vulnerabilities: command execution, code execution, os command injection...
Affected productsExternal IDs
db: NVD ids: CVE-2023-2587, CVE-2023-32350, CVE-2023-2588, CVE-2023-32348, CVE-2023-2586, CVE-2023-32349, CVE-2023-32347, CVE-2023-32346

Trust: 3.75

Fetched: May 12, 2023, 9:14 a.m., Published: May 9, 2023, midnight
Vulnerabilities: security feature bypass, feature bypass
Affected productsExternal IDs
db: NVD ids: CVE-2023-24932

Trust: 4.75

Fetched: May 12, 2023, 9:13 a.m., Published: -
Vulnerabilities: code execution, security feature bypass, denial of service...
Affected productsExternal IDs
db: NVD ids: CVE-2023-24954, CVE-2023-24932, CVE-2023-29325, CVE-2023-24941, CVE-2023-29324, CVE-2013-3900, CVE-2023-28283, CVE-2023-24903, CVE-2023-24949, CVE-2023-24950, CVE-2023-29336, CVE-2023-24902, CVE-2023-24955, CVE-2023-24943

Trust: 4.5

Fetched: May 12, 2023, 9:13 a.m., Published: May 12, 2023, midnight
Vulnerabilities: security feature bypass, code execution, feature bypass
Affected productsExternal IDs
vendor: google model: android
db: NVD ids: CVE-2023-24941, CVE-2023-24932, CVE-2023-29325, CVE-2023-29336

Trust: 4.25

Fetched: May 10, 2023, 9:17 a.m., Published: May 3, 2023, 9:37 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: amazon model: fire tv
db: NVD ids: CVE-2023-1384, CVE-2023-1383, CVE-2023-1385

Trust: 3.75

Fetched: May 10, 2023, 9:16 a.m., Published: May 1, 2023, 7:21 p.m.
Vulnerabilities: code execution, privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2023-1968, CVE-2023-1966

Trust: 4.75

Fetched: May 10, 2023, 9:15 a.m., Published: May 5, 2023, 7:30 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: google model: android
vendor: google model: chrome
db: NVD ids: CVE-2023-0266

Trust: 3.5

Fetched: May 10, 2023, 9:15 a.m., Published: March 10, 2023, midnight
Vulnerabilities: default password, code execution, privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2023-0888
Related entries in the VARIoT vulnerabilities database: VAR-202304-1936, VAR-202304-1913, VAR-202304-1973

Trust: 5.5

Fetched: May 10, 2023, 9:14 a.m., Published: May 1, 2023, midnight
Vulnerabilities: buffer overflow, path traversal, information exposure...
Affected productsExternal IDs
vendor: zyxel model: nwa1123-ac
db: NVD ids: CVE-2023-22917, CVE-2023-22914, CVE-2023-22916, CVE-2023-22918, CVE-2023-22913, CVE-2023-22915

Trust: 3.5

Fetched: May 9, 2023, 9:17 a.m., Published: April 13, 2023, midnight
Vulnerabilities: lock bypass
Affected productsExternal IDs
vendor: apple model: ipad
vendor: apple model: iphone
vendor: apple model: macos
vendor: apple model: icloud

Trust: 4.25

Fetched: May 9, 2023, 9:16 a.m., Published: May 9, 2022, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: amazon model: fire tv
db: NVD ids: CVE-2023-1385, CVE-2023-1384, CVE-2023-1383

Trust: 5.0

Fetched: May 9, 2023, 9:16 a.m., Published: May 8, 2023, 5:17 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2023-25717
Related entries in the VARIoT vulnerabilities database: VAR-202204-1376

Trust: 3.75

Fetched: May 9, 2023, 9:15 a.m., Published: April 11, 2023, 6:22 p.m.
Vulnerabilities: code execution, denial of service
Affected productsExternal IDs
db: NVD ids: CVE-2023-28302, CVE-2023-21769, CVE-2023-28231, CVE-2022-24521, CVE-2022-37969, CVE-2023-23376, CVE-2023-28250, CVE-2023-21554, CVE-2023-28252

Trust: 3.0

Fetched: May 9, 2023, 9:14 a.m., Published: Dec. 18, 2020, midnight
Vulnerabilities: privilege escalation, denial of service
Affected productsExternal IDs

Trust: 4.5

Fetched: May 9, 2023, 9:13 a.m., Published: May 4, 2023, midnight
Vulnerabilities: directory traversal, path traversal, buffer overflow...
Affected productsExternal IDs
db: NVD ids: CVE-2022-3183, CVE-2022-3184, CVE-2022-3189, CVE-2022-3187, CVE-2022-3186, CVE-2022-46738, CVE-2022-47311, CVE-2022-4945, CVE-2022-46658, CVE-2022-3185, CVE-2022-47320, CVE-2022-3188

Trust: 4.0

Fetched: May 9, 2023, 9:13 a.m., Published: Feb. 7, 2023, 8:15 a.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs

Trust: 3.0

Fetched: May 7, 2023, 9:16 a.m., Published: May 2, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: amazon model: fire tv
Related entries in the VARIoT vulnerabilities database: VAR-202303-1268

Trust: 4.75

Fetched: May 7, 2023, 9:15 a.m., Published: May 2, 2023, 7:38 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: trend model: micro maximum security
vendor: trend model: home network security
vendor: trend model: antivirus
vendor: trend model: security
vendor: tp-link model: routers
vendor: trend micro model: micro maximum security
vendor: trend micro model: home network security
vendor: trend micro model: antivirus
vendor: trend micro model: security
db: NVD ids: CVE-2023-1389

Trust: 5.75

Fetched: May 7, 2023, 9:15 a.m., Published: April 7, 2023, 10:50 a.m.
Vulnerabilities: code execution, command injection, cross-site scripting
Affected productsExternal IDs
vendor: sophos model: firewall
vendor: sophos model: sophos web appliance
vendor: sophos model: web appliance
db: NVD ids: CVE-2020-36692, CVE-2023-1671, CVE-2022-4934
Related entries in the VARIoT vulnerabilities database: VAR-202304-0672

Trust: 5.5

Fetched: May 7, 2023, 9:14 a.m., Published: April 11, 2023, midnight
Vulnerabilities: information disclosure, code execution, privilege escalation
Affected productsExternal IDs
vendor: siemens model: scalance
vendor: siemens model: sicam a8000
vendor: siemens model: sicam
vendor: siemens model: solid edge
vendor: siemens model: tia portal
vendor: siemens model: siprotec 5
vendor: siemens model: teamcenter visualization
vendor: siemens model: siprotec
vendor: siemens model: simatic
vendor: siemens model: jt2go
vendor: siemens model: teamcenter
vendor: siemens model: scalance x-200irt
vendor: schneider model: ecostruxure control expert
vendor: schneider model: control expert
vendor: opc foundation model: local discovery server
vendor: codesys model: codesys
vendor: codesys model: linux
vendor: codesys model: web server
vendor: codesys model: control
vendor: schneider electric model: ecostruxure control expert
vendor: schneider electric model: control expert
db: NVD ids: CVE-2023-28489