VARIoT news about IoT security

Trust: 4.5

Fetched: Jan. 17, 2025, 9:34 a.m., Published: Jan. 15, 2025, 2:19 p.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: node.js model: node.js
vendor: fortigate model: fortios
db: NVD ids: CVE-2024-55591

Trust: 3.25

Fetched: Jan. 17, 2025, 9:33 a.m., Published: Jan. 15, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2024-57857

Trust: 4.25

Fetched: Jan. 17, 2025, 9:32 a.m., Published: Jan. 16, 2025, 3:16 p.m.
Vulnerabilities: path traversal
Affected productsExternal IDs
db: NVD ids: CVE-2024-13159, CVE-2025-0070, CVE-2025-0066, CVE-2024-13160, CVE-2024-10811, CVE-2024-13161

Trust: 4.75

Fetched: Jan. 17, 2025, 9:27 a.m., Published: Jan. 7, 2025, 7 p.m.
Vulnerabilities: code execution, privilege escalation, path traversal...
Affected productsExternal IDs
vendor: mitel model: micollab
db: NVD ids: CVE-2024-11639, CVE-2024-35286, CVE-2024-50623, CVE-2024-11773, CVE-2024-41713, CVE-2024-11772

Trust: 4.5

Fetched: Jan. 17, 2025, 9:26 a.m., Published: Jan. 16, 2025, 3:08 a.m.
Vulnerabilities: information disclosure, denial of service, code execution...
Affected productsExternal IDs
db: NVD ids: CVE-2025-21301, CVE-2025-21218, CVE-2025-21302, CVE-2025-21296, CVE-2025-21293, CVE-2025-21265, CVE-2025-21193, CVE-2025-21292, CVE-2025-21343, CVE-2025-21364, CVE-2025-21256, CVE-2025-21187, CVE-2025-21348, CVE-2025-21186, CVE-2025-21244, CVE-2025-21219, CVE-2025-21250, CVE-2025-21266, CVE-2025-21238, CVE-2025-21229, CVE-2025-21225, CVE-2025-21323, CVE-2025-21311, CVE-2025-21288, CVE-2025-21268, CVE-2025-21233, CVE-2025-21281, CVE-2025-21227, CVE-2025-21402, CVE-2025-21335, CVE-2025-21417, CVE-2025-21340, CVE-2025-21278, CVE-2025-21215, CVE-2025-21362, CVE-2025-21223, CVE-2025-21273, CVE-2025-21287, CVE-2025-21176, CVE-2025-21310, CVE-2025-21189, CVE-2025-21356, CVE-2025-21291, CVE-2025-21345, CVE-2025-21338, CVE-2025-21409, CVE-2025-21213, CVE-2025-21314, CVE-2025-21354, CVE-2025-21242, CVE-2025-21284, CVE-2025-21389, CVE-2025-21306, CVE-2025-21277, CVE-2025-21382, CVE-2025-21320, CVE-2025-21232, CVE-2025-21275, CVE-2025-21246, CVE-2025-21309, CVE-2025-21321, CVE-2025-21285, CVE-2025-21251, CVE-2025-21286, CVE-2025-21339, CVE-2025-21295, CVE-2025-21249, CVE-2025-21317, CVE-2025-21331, CVE-2025-21307, CVE-2025-21360, CVE-2025-21173, CVE-2025-21313, CVE-2025-21378, CVE-2025-21298, CVE-2025-21202, CVE-2025-21241, CVE-2025-21210, CVE-2025-21318, CVE-2025-21289, CVE-2025-21395, CVE-2025-21346, CVE-2025-21365, CVE-2025-21214, CVE-2025-21334, CVE-2025-21326, CVE-2025-21308, CVE-2025-21327, CVE-2025-21261, CVE-2025-21299, CVE-2025-21315, CVE-2025-21258, CVE-2025-21324, CVE-2025-21276, CVE-2025-21344, CVE-2025-21252, CVE-2025-21257, CVE-2025-21385, CVE-2025-21290, CVE-2025-21341, CVE-2025-21211, CVE-2025-21297, CVE-2025-21372, CVE-2025-21411, CVE-2025-21231, CVE-2025-21234, CVE-2025-21316, CVE-2025-21361, CVE-2025-21380, CVE-2025-21269, CVE-2025-21245, CVE-2025-21305, CVE-2025-21336, CVE-2025-21363, CVE-2025-21413, CVE-2025-21312, CVE-2025-21172, CVE-2025-21270, CVE-2025-21272, CVE-2025-21237, CVE-2025-21236, CVE-2025-21239, CVE-2025-21243, CVE-2025-21224, CVE-2025-21280, CVE-2025-21304, CVE-2025-21228, CVE-2025-21207, CVE-2025-21226, CVE-2025-21374, CVE-2025-21303, CVE-2025-21235, CVE-2025-21328, CVE-2025-21282, CVE-2025-21332, CVE-2025-21178, CVE-2025-21300, CVE-2025-21366, CVE-2025-21255, CVE-2025-21260, CVE-2025-21393, CVE-2025-21357, CVE-2025-21274, CVE-2025-21271, CVE-2025-21220, CVE-2025-21248, CVE-2025-21403, CVE-2025-21171, CVE-2025-21370, CVE-2025-21263, CVE-2025-21405, CVE-2025-21319, CVE-2025-21217, CVE-2025-21294, CVE-2025-21330, CVE-2025-21333, CVE-2025-21240, CVE-2025-21230, CVE-2025-21329

Trust: 4.75

Fetched: Jan. 17, 2025, 9:25 a.m., Published: Jan. 14, 2025, 4:38 p.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: node.js model: node.js
vendor: fortigate model: fortios
db: NVD ids: CVE-2024-55591

Trust: 5.75

Fetched: Jan. 17, 2025, 9:24 a.m., Published: -
Vulnerabilities: authentication vulnerability, code execution, request forgery...
Affected productsExternal IDs
vendor: sonicwall model: ssl vpn
vendor: sonicwall model: sma100
vendor: sonicwall model: sonicos
vendor: sonicwall model: sma1000
db: NVD ids: CVE-2024-53706, CVE-2024-53704, CVE-2024-53705, CVE-2024-40762

Trust: 5.5

Fetched: Jan. 17, 2025, 9:22 a.m., Published: -
Vulnerabilities: code execution, buffer overflow, path traversal...
Affected productsExternal IDs
vendor: canonical model: ubuntu
db: NVD ids: CVE-2024-12747, CVE-2024-12087, CVE-2024-12085, CVE-2024-12084, CVE-2024-12086, CVE-2024-12088

Trust: 4.5

Fetched: Jan. 17, 2025, 9:19 a.m., Published: Jan. 15, 2025, 2:19 p.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: node.js model: node.js
vendor: fortigate model: fortios
db: NVD ids: CVE-2024-55591

Trust: 4.25

Fetched: Jan. 17, 2025, 9:18 a.m., Published: Jan. 17, 2024, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
db: NVD ids: CVE-2025-21207

Trust: 4.0

Fetched: Jan. 17, 2025, 9:18 a.m., Published: Jan. 1, 2025, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-43096

Trust: 3.5

Fetched: Jan. 17, 2025, 9:17 a.m., Published: Jan. 1, 2025, 1:02 p.m.
Vulnerabilities: code execution, denial of service
Affected productsExternal IDs
vendor: cisco model: umbrella

Trust: 3.0

Fetched: Jan. 17, 2025, 9:16 a.m., Published: Jan. 16, 2025, 10:11 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: fortigate model: fortios

Trust: 4.0

Fetched: Jan. 17, 2025, 9:15 a.m., Published: Jan. 14, 2025, 7:08 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2025-21395, CVE-2025-21333, CVE-2025-21186, CVE-2025-21334, CVE-2025-21366, CVE-2025-21335, CVE-2025-21275, CVE-2025-21308

Trust: 4.5

Fetched: Jan. 17, 2025, 9:15 a.m., Published: Jan. 14, 2025, 8 p.m.
Vulnerabilities: response splitting vulnerability, denial of service, access control vulnerability...
Affected productsExternal IDs
vendor: node.js model: node.js
vendor: fortigate model: fortios
db: NVD ids: CVE-2024-55591

Trust: 5.5

Fetched: Jan. 17, 2025, 9:14 a.m., Published: -
Vulnerabilities: cross-site scripting
Affected productsExternal IDs
db: NVD ids: CVE-2025-0193

Trust: 6.25

Fetched: Jan. 17, 2025, 9:14 a.m., Published: Jan. 14, 2025, 9:04 p.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: fortigate model: fortios
db: NVD ids: CVE-2024-55591
Related entries in the VARIoT vulnerabilities database: VAR-202210-0198

Trust: 4.75

Fetched: Jan. 17, 2025, 9:13 a.m., Published: Jan. 16, 2025, 12:50 p.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: fortigate model: fortios
db: NVD ids: CVE-2024-55591, CVE-2022-40684
Related entries in the VARIoT vulnerabilities database: VAR-202412-2770

Trust: 3.75

Fetched: Jan. 17, 2025, 9:10 a.m., Published: May 17, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: hikvision model: hikvision
db: NVD ids: CVE-2024-12569

Trust: 4.5

Fetched: Jan. 17, 2025, 9:09 a.m., Published: Sept. 8, 2023, 7:11 p.m.
Vulnerabilities: code execution, buffer overflow
Affected productsExternal IDs
vendor: apple model: ipad air
vendor: apple model: watch
vendor: apple model: iphone
vendor: apple model: ios
vendor: apple model: macos
vendor: apple model: ipad
vendor: apple model: watchos