VARIoT news about IoT security

Trust: 4.5

Fetched: Feb. 14, 2025, 9:46 a.m., Published: May 14, 2025, midnight
Vulnerabilities: buffer overflow, code execution
Affected productsExternal IDs
vendor: google model: android

Trust: 5.0

Fetched: Feb. 14, 2025, 9:44 a.m., Published: Feb. 13, 2025, midnight
Vulnerabilities: arbitrary command execution, privilege escalation, command injection...
Affected productsExternal IDs
db: NVD ids: CVE-2024-40891, CVE-2025-21391, CVE-2025-21418, CVE-2024-40890

Trust: 3.5

Fetched: Feb. 14, 2025, 9:44 a.m., Published: Feb. 13, 2025, 8:10 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: iphone
vendor: apple model: macos
db: NVD ids: CVE-2025-24200

Trust: 4.5

Fetched: Feb. 14, 2025, 9:43 a.m., Published: Feb. 12, 2025, 10:14 a.m.
Vulnerabilities: memory corruption, code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-46666, CVE-2024-46668

Trust: 3.0

Fetched: Feb. 14, 2025, 9:43 a.m., Published: Feb. 12, 2025, 6:15 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: macos
Related entries in the VARIoT vulnerabilities database: VAR-202501-2383, VAR-202501-1996

Trust: 4.75

Fetched: Feb. 14, 2025, 9:42 a.m., Published: Feb. 1, 2025, midnight
Vulnerabilities: integer overflow, denial of service, path traversal
Affected productsExternal IDs
db: NVD ids: CVE-2024-46665, CVE-2024-46670, CVE-2024-36504, CVE-2024-52963, CVE-2024-48884, CVE-2024-46666, CVE-2024-54021, CVE-2024-48885, CVE-2024-46669, CVE-2024-46668

Trust: 3.0

Fetched: Feb. 14, 2025, 9:41 a.m., Published: May 13, 2024, 5:53 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: dell model: bios
vendor: dell model: optiplex

Trust: 3.75

Fetched: Feb. 14, 2025, 9:34 a.m., Published: Feb. 12, 2025, 9:14 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2025-0626, CVE-2024-12248, CVE-2025-0683

Trust: 5.5

Fetched: Feb. 14, 2025, 9:32 a.m., Published: Feb. 11, 2025, 9:30 p.m.
Vulnerabilities: feature bypass, code execution, denial of service...
Affected productsExternal IDs
vendor: node.js model: node.js
db: NVD ids: CVE-2025-21420, CVE-2025-21419, CVE-2025-21201, CVE-2025-21392, CVE-2025-0451, CVE-2025-21406, CVE-2025-21177, CVE-2025-21391, CVE-2025-21206, CVE-2024-38193, CVE-2025-24039, CVE-2025-21400, CVE-2025-21377, CVE-2025-21351, CVE-2025-21418, CVE-2025-21407, CVE-2025-21283, CVE-2025-21267, CVE-2025-21387, CVE-2025-21394, CVE-2025-21208, CVE-2025-21198, CVE-2025-21200, CVE-2025-21352, CVE-2025-21190, CVE-2025-21347, CVE-2025-21397, CVE-2025-21254, CVE-2025-21379, CVE-2025-21414, CVE-2025-21368, CVE-2025-21371, CVE-2025-21308, CVE-2025-21188, CVE-2025-21212, CVE-2025-21342, CVE-2025-21383, CVE-2025-21182, CVE-2025-21373, CVE-2025-21349, CVE-2025-21408, CVE-2025-24036, CVE-2025-21216, CVE-2025-21367, CVE-2025-24042, CVE-2025-21184, CVE-2025-21259, CVE-2025-21410, CVE-2025-21350, CVE-2025-21322, CVE-2025-21279, CVE-2025-21179, CVE-2025-21375, CVE-2025-21359, CVE-2025-21194, CVE-2025-21390, CVE-2025-21337, CVE-2025-21369, CVE-2025-0444, CVE-2025-21253, CVE-2025-21381, CVE-2025-21404, CVE-2023-32002, CVE-2025-21358, CVE-2025-21183, CVE-2025-21181, CVE-2025-21386, CVE-2025-21376, CVE-2025-0445

Trust: 5.0

Fetched: Feb. 14, 2025, 9:31 a.m., Published: Feb. 13, 2025, 7:40 a.m.
Vulnerabilities: file upload vulnerability
Affected productsExternal IDs
db: NVD ids: CVE-2025-1070

Trust: 4.25

Fetched: Feb. 14, 2025, 9:30 a.m., Published: Feb. 12, 2025, 9 a.m.
Vulnerabilities: certificate validation vulnerability
Affected productsExternal IDs
db: NVD ids: CVE-2024-11621, CVE-2025-1193

Trust: 4.5

Fetched: Feb. 14, 2025, 9:30 a.m., Published: Feb. 12, 2025, 5 p.m.
Vulnerabilities: os command injection, command injection
Affected productsExternal IDs
vendor: palo model: pan-os
vendor: palo model: firewall
vendor: palo model: networks
vendor: palo alto networks model: pan-os
vendor: palo alto networks model: firewall
vendor: palo alto networks model: networks
db: NVD ids: CVE-2025-0110

Trust: 4.25

Fetched: Feb. 14, 2025, 9:28 a.m., Published: Feb. 13, 2025, 6:46 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: lexmark model: lexmark
db: NVD ids: CVE-2024-11345

Trust: 5.5

Fetched: Feb. 14, 2025, 9:28 a.m., Published: Feb. 11, 2025, 6:47 p.m.
Vulnerabilities: feature bypass, code execution, denial of service...
Affected productsExternal IDs
vendor: node.js model: node.js
db: NVD ids: CVE-2025-21420, CVE-2025-21419, CVE-2025-21201, CVE-2025-21392, CVE-2025-21406, CVE-2025-21391, CVE-2025-21206, CVE-2025-24039, CVE-2025-21400, CVE-2025-21351, CVE-2025-21377, CVE-2025-21418, CVE-2025-21407, CVE-2023-24932, CVE-2025-21387, CVE-2025-21176, CVE-2025-21394, CVE-2025-21208, CVE-2025-21198, CVE-2025-21352, CVE-2025-21200, CVE-2025-21190, CVE-2025-21347, CVE-2025-21397, CVE-2025-21254, CVE-2025-21379, CVE-2025-21414, CVE-2025-21368, CVE-2025-21371, CVE-2025-21188, CVE-2025-21212, CVE-2025-21383, CVE-2025-21182, CVE-2025-21373, CVE-2025-21349, CVE-2025-21178, CVE-2025-24036, CVE-2025-21216, CVE-2025-21367, CVE-2025-24042, CVE-2025-21184, CVE-2025-21259, CVE-2025-21172, CVE-2025-21410, CVE-2025-21350, CVE-2025-21179, CVE-2025-21322, CVE-2025-21375, CVE-2025-21359, CVE-2025-21194, CVE-2025-21390, CVE-2025-21337, CVE-2025-21369, CVE-2025-21381, CVE-2025-21183, CVE-2023-32002, CVE-2025-21358, CVE-2025-21181, CVE-2025-21386, CVE-2025-21376
Related entries in the VARIoT vulnerabilities database: VAR-202501-2383, VAR-202501-1996

Trust: 5.5

Fetched: Feb. 14, 2025, 9:27 a.m., Published: Jan. 10, 2023, midnight
Vulnerabilities: integer overflow, path traversal
Affected productsExternal IDs
vendor: siemens model: ruggedcom
db: NVD ids: CVE-2024-46665, CVE-2024-46670, CVE-2024-36504, CVE-2024-52963, CVE-2024-48884, CVE-2024-46666, CVE-2024-54021, CVE-2024-48885, CVE-2024-46669, CVE-2024-46668

Trust: 6.0

Fetched: Feb. 14, 2025, 9:27 a.m., Published: Jan. 14, 2025, midnight
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: node.js model: node.js
db: NVD ids: CVE-2025-24472, CVE-2024-55591

Trust: 4.25

Fetched: Feb. 14, 2025, 9:26 a.m., Published: Feb. 13, 2025, 6:51 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: lexmark model: lexmark
db: NVD ids: CVE-2024-11344

Trust: 3.5

Fetched: Feb. 14, 2025, 9:25 a.m., Published: -
Vulnerabilities: information exposure, command injection, cross-site scripting
Affected productsExternal IDs
db: NVD ids: CVE-2024-5411, CVE-2024-5410

Trust: 4.25

Fetched: Feb. 14, 2025, 9:25 a.m., Published: Feb. 13, 2025, 9:55 p.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
db: NVD ids: CVE-2025-24836

Trust: 4.75

Fetched: Feb. 14, 2025, 9:24 a.m., Published: May 14, 2025, midnight
Vulnerabilities: feature bypass, security bypass, security feature bypass
Affected productsExternal IDs
db: NVD ids: CVE-2025-21194