VARIoT news about IoT security

Trust: 5.0

Fetched: Jan. 15, 2025, 9:33 a.m., Published: Jan. 5, 2025, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
db: NVD ids: CVE-2024-7322

Trust: 3.75

Fetched: Jan. 15, 2025, 9:32 a.m., Published: Jan. 15, 2025, 12:14 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2025-21308, CVE-2025-21334, CVE-2025-21333, CVE-2024-38014, CVE-2020-16885, CVE-2025-21335, CVE-2025-21307, CVE-2025-21275, CVE-2025-21298

Trust: 5.25

Fetched: Jan. 15, 2025, 9:32 a.m., Published: Jan. 14, 2025, 8:12 a.m.
Vulnerabilities: directory traversal, denial of service, code execution...
Affected productsExternal IDs
vendor: mitel model: micollab
vendor: palo model: firewall
vendor: palo model: networks
vendor: palo model: ssl vpn
vendor: palo model: pan-os
db: NVD ids: CVE-2024-53677, CVE-2023-50164, CVE-2023-28461, CVE-2024-49138, CVE-2024-35286, CVE-2024-35250, CVE-2024-3393, CVE-2024-11667, CVE-2024-41713

Trust: 3.0

Fetched: Jan. 15, 2025, 9:30 a.m., Published: Jan. 15, 2025, 9:30 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: fortigate model: fortios

Trust: 4.75

Fetched: Jan. 15, 2025, 9:30 a.m., Published: Jan. 14, 2025, midnight
Vulnerabilities: buffer overflow
Affected productsExternal IDs
vendor: trend model: security
db: NVD ids: CVE-2023-46805, CVE-2025-0282, CVE-2024-21887

Trust: 3.0

Fetched: Jan. 15, 2025, 9:22 a.m., Published: Jan. 20, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: realtek model: realtek sdk

Trust: 3.25

Fetched: Jan. 15, 2025, 9:21 a.m., Published: Jan. 15, 2025, 3:42 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: iphone

Trust: 4.25

Fetched: Jan. 15, 2025, 9:21 a.m., Published: Jan. 5, 2025, midnight
Vulnerabilities: sql injection, default credentials, cross-site scripting
Affected productsExternal IDs
vendor: wireshark model: wireshark

Trust: 4.5

Fetched: Jan. 15, 2025, 9:19 a.m., Published: Jan. 14, 2025, midnight
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: sonicwall model: ssl vpn
vendor: sonicwall model: sonicos
vendor: fortigate model: fortios
db: NVD ids: CVE-2024-40766, CVE-2024-55591
Related entries in the VARIoT vulnerabilities database: VAR-202412-2435

Trust: 5.75

Fetched: Jan. 14, 2025, 10 a.m., Published: Dec. 30, 2024, 7:44 a.m.
Vulnerabilities: improper access control
Affected productsExternal IDs
vendor: d-link model: router
vendor: d-link model: dir-823g
db: NVD ids: CVE-2024-13030

Trust: 4.25

Fetched: Jan. 14, 2025, 9:59 a.m., Published: Jan. 14, 7170, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: canonical model: ubuntu
db: NVD ids: CVE-2024-49909, CVE-2024-47704, CVE-2024-49915, CVE-2024-49918, CVE-2024-49904, CVE-2024-49899, CVE-2024-49893, CVE-2024-49967, CVE-2024-49910, CVE-2024-49907, CVE-2024-49911, CVE-2024-49921, CVE-2024-49914, CVE-2024-49917, CVE-2024-49916, CVE-2024-49898, CVE-2024-49897, CVE-2024-49896, CVE-2024-50264, CVE-2024-49923, CVE-2024-49913, CVE-2024-49906, CVE-2024-49912, CVE-2024-49920, CVE-2024-49905, CVE-2024-49919, CVE-2024-49922, CVE-2024-49908, CVE-2024-53057

Trust: 3.75

Fetched: Jan. 14, 2025, 9:58 a.m., Published: Jan. 13, 2025, 8:52 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: apple model: iphone
vendor: apple model: macbook
Related entries in the VARIoT vulnerabilities database: VAR-202412-2453

Trust: 3.75

Fetched: Jan. 14, 2025, 9:57 a.m., Published: Dec. 19, 2024, 8:16 a.m.
Vulnerabilities: path traversal, improper validation
Affected productsExternal IDs
db: NVD ids: CVE-2023-34990, CVE-2024-48889

Trust: 4.75

Fetched: Jan. 14, 2025, 9:56 a.m., Published: Feb. 13, 2024, 7 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: four-faith model: four-faith
vendor: four-faith model: four-faith router
db: NVD ids: CVE-2024-12856

Trust: 3.75

Fetched: Jan. 14, 2025, 9:53 a.m., Published: March 14, 2024, midnight
Vulnerabilities: default credentials, buffer overflow, code execution...
Affected productsExternal IDs
db: NVD ids: CVE-2024-43653, CVE-2024-43662, CVE-2024-43648, CVE-2024-43655, CVE-2024-43660, CVE-2024-43659, CVE-2024-43661, CVE-2024-43663, CVE-2024-43649, CVE-2024-43652, CVE-2024-43654, CVE-2024-43650, CVE-2024-43656, CVE-2024-43651, CVE-2024-43657, CVE-2024-43658

Trust: 6.0

Fetched: Jan. 14, 2025, 9:52 a.m., Published: Jan. 8, 2025, 2:49 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: dell model: bios
db: NVD ids: CVE-2025-22395

Trust: 5.25

Fetched: Jan. 14, 2025, 9:52 a.m., Published: Jan. 13, 2025, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: samsung model: samsung
db: NVD ids: CVE-2024-49415

Trust: 4.25

Fetched: Jan. 14, 2025, 9:51 a.m., Published: Dec. 17, 2024, 8:15 p.m.
Vulnerabilities: file upload vulnerability
Affected productsExternal IDs
db: NVD ids: CVE-2024-55515
Related entries in the VARIoT vulnerabilities database: VAR-202403-2416

Trust: 5.25

Fetched: Jan. 14, 2025, 9:49 a.m., Published: Dec. 22, 2024, 9:43 a.m.
Vulnerabilities: buffer overflow, feature bypass, command execution...
Affected productsExternal IDs
vendor: palo alto networks model: pan-os
vendor: palo alto networks model: firewall
vendor: palo alto networks model: ssl vpn
vendor: palo alto networks model: networks
vendor: palo model: pan-os
vendor: palo model: firewall
vendor: palo model: ssl vpn
vendor: palo model: networks
vendor: google model: google chrome
vendor: google model: chrome
vendor: google model: nexus
vendor: check point model: management server
vendor: check point model: check point
vendor: checkpoint model: management server
vendor: checkpoint model: check point
vendor: cisco model: series switches
vendor: cisco model: cisco nx-os
vendor: cisco model: nx-os
vendor: cisco model: spark
vendor: cisco model: nexus 3000
vendor: cisco model: series
vendor: cisco model: nx-os software
vendor: cisco model: nexus
db: NVD ids: CVE-2024-21887, CVE-2024-23897, CVE-2023-22527, CVE-2024-38112, CVE-2024-21762, CVE-2024-3400, CVE-2024-9474, CVE-2024-24919, CVE-2024-0012, CVE-2024-5274, CVE-2024-21412, CVE-2024-21893, CVE-2024-1709, CVE-2024-42448, CVE-2024-49138, CVE-2024-37085, CVE-2023-46805, CVE-2024-20399, CVE-2024-11667, CVE-2024-9264, CVE-2024-36991, CVE-2023-48788

Trust: 4.0

Fetched: Jan. 14, 2025, 9:48 a.m., Published: Jan. 7, 2025, midnight
Vulnerabilities: privilege management vulnerability
Affected productsExternal IDs