VARIoT news about IoT security

Trust: 3.25

Fetched: Jan. 12, 2025, 9:19 a.m., Published: Jan. 11, 2025, 7:13 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: samsung model: samsung

Trust: 3.0

Fetched: Jan. 12, 2025, 9:17 a.m., Published: June 24, 2022, midnight
Vulnerabilities: default credentials
Affected productsExternal IDs
Related entries in the VARIoT vulnerabilities database: VAR-201504-0235, VAR-201504-0031, VAR-201504-0234

Trust: 4.75

Fetched: Jan. 12, 2025, 9:16 a.m., Published: Jan. 12, 2024, midnight
Vulnerabilities: resource exhaustion
Affected productsExternal IDs
vendor: siemens model: simatic net pc-software
vendor: siemens model: tia portal
vendor: siemens model: simatic net
vendor: siemens model: simatic hmi comfort panels
vendor: siemens model: simatic wincc runtime advanced
vendor: siemens model: siemens simatic hmi
vendor: siemens model: simatic hmi panels
vendor: siemens model: simatic hmi mobile panel
vendor: siemens model: simatic wincc runtime professional
vendor: siemens model: simatic wincc
vendor: siemens model: wincc tia portal
vendor: siemens model: simatic hmi mobile panel 277
vendor: siemens model: simatic wincc runtime
vendor: siemens model: simatic wincc comfort
vendor: siemens model: wincc runtime advanced
vendor: siemens model: simatic hmi basic panels 1st generation
vendor: siemens model: simatic hmi multi panels
vendor: siemens model: simatic net pc
vendor: siemens model: simatic hmi
vendor: siemens model: simatic
vendor: siemens model: wincc
vendor: siemens model: simatic hmi basic panels 2nd generation
vendor: siemens model: simatic automation tool
db: NVD ids: CVE-2015-2823, CVE-2015-1601, CVE-2015-2822

Trust: 4.25

Fetched: Jan. 12, 2025, 9:15 a.m., Published: Jan. 1, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: dahua model: network camera
vendor: dahua model: camera
vendor: dahua model: ip camera
vendor: dahua model: web service
vendor: axis model: ip cameras
vendor: axis model: network camera
vendor: axis model: axis
db: NVD ids: CVE-2022-30563

Trust: 3.0

Fetched: Jan. 10, 2025, 10:06 a.m., Published: Dec. 26, 2024, 9:34 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: parallels model: parallels desktop
vendor: parallels model: desktop

Trust: 5.75

Fetched: Jan. 10, 2025, 10:05 a.m., Published: Jan. 8, 2025, 7:09 p.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: four-faith model: four-faith router
vendor: four-faith model: four-faith
db: NVD ids: CVE-2024-12856, CVE-2013-3307, CVE-2021-35394, CVE-2024-8957

Trust: 4.75

Fetched: Jan. 10, 2025, 10:04 a.m., Published: Jan. 8, 2025, 10:45 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: four-faith model: four-faith
db: NVD ids: CVE-2024-12856

Trust: 5.5

Fetched: Jan. 10, 2025, 10:04 a.m., Published: Jan. 9, 2025, 7:24 a.m.
Vulnerabilities: os command injection, cross-site scripting, sql injection...
Affected productsExternal IDs
vendor: palo alto networks model: networks
vendor: palo alto networks model: firewall
vendor: palo model: networks
vendor: palo model: firewall
db: NVD ids: CVE-2025-0107, CVE-2025-0104, CVE-2025-0106, CVE-2025-0103, CVE-2025-0105
Related entries in the VARIoT vulnerabilities database: VAR-201505-0274, VAR-202003-1707, VAR-201803-1048

Trust: 4.5

Fetched: Jan. 10, 2025, 10:03 a.m., Published: Jan. 8, 2025, 10:34 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: asus model: routers
vendor: asus model: asus
vendor: asus model: router
vendor: four-faith model: four-faith
db: NVD ids: CVE-2014-8361, CVE-2024-12856, CVE-2020-9054, CVE-2017-17215

Trust: 5.0

Fetched: Jan. 10, 2025, 10:03 a.m., Published: Jan. 2, 2025, 4:33 a.m.
Vulnerabilities: code injection
Affected productsExternal IDs
vendor: node.js model: node.js
db: NVD ids: CVE-2024-54152

Trust: 3.25

Fetched: Jan. 10, 2025, 10:03 a.m., Published: Jan. 10, 7182, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: canonical model: ubuntu

Trust: 3.25

Fetched: Jan. 10, 2025, 10:02 a.m., Published: Jan. 10, 7182, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: canonical model: ubuntu

Trust: 4.75

Fetched: Jan. 10, 2025, 10:02 a.m., Published: Dec. 26, 2024, 2:21 a.m.
Vulnerabilities: request forgery, authentication vulnerability, weak password...
Affected productsExternal IDs
db: NVD ids: CVE-2024-48874, CVE-2024-52324, CVE-2024-47146, CVE-2024-47547
Related entries in the VARIoT vulnerabilities database: VAR-202501-0708

Trust: 6.0

Fetched: Jan. 10, 2025, 10:01 a.m., Published: Jan. 7, 2025, 9:01 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: google model: home
db: NVD ids: CVE-2024-20149, CVE-2024-20143, CVE-2024-20140, CVE-2024-20150, CVE-2024-20154

Trust: 3.0

Fetched: Jan. 10, 2025, 10:01 a.m., Published: Jan. 9, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: sonicwall model: sonicos

Trust: 3.5

Fetched: Jan. 10, 2025, 10:01 a.m., Published: Jan. 8, 2025, 7:16 p.m.
Vulnerabilities: buffer overflow, authentication bypass, request forgery...
Affected productsExternal IDs
db: NVD ids: CVE-2025-0283, CVE-2021-22894, CVE-2024-21888, CVE-2023-46805, CVE-2019-11539, CVE-2020-8243, CVE-2025-0282, CVE-2019-11510, CVE-2020-8260, CVE-2021-22893, CVE-2024-21887, CVE-2024-21893, CVE-2020-8218, CVE-2021-22899, CVE-2021-22900
Related entries in the VARIoT vulnerabilities database: VAR-201307-0483

Trust: 5.5

Fetched: Jan. 10, 2025, 9:59 a.m., Published: Jan. 10, 2013, midnight
Vulnerabilities: integer overflow, denial of service, code execution...
Affected productsExternal IDs
vendor: canary model: canary
db: NVD ids: CVE-2013-2028

Trust: 5.25

Fetched: Jan. 10, 2025, 9:58 a.m., Published: Jan. 8, 2025, 9:24 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: four-faith model: four-faith
db: NVD ids: CVE-2024-12856

Trust: 5.5

Fetched: Jan. 10, 2025, 9:57 a.m., Published: Jan. 7, 2025, 2:54 p.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: huawei model: huawei
vendor: huawei model: warsaw
vendor: asus model: routers
vendor: asus model: asus
vendor: asus model: router
vendor: kguard model: kguard dvr
vendor: four-faith model: four-faith
db: NVD ids: CVE-2024-12856

Trust: 5.25

Fetched: Jan. 10, 2025, 9:56 a.m., Published: Jan. 8, 2025, 5 p.m.
Vulnerabilities: os command injection, cross-site scripting, sql injection...
Affected productsExternal IDs
vendor: palo alto networks model: firewall
vendor: palo alto networks model: pan-os
vendor: palo alto networks model: networks
vendor: palo model: firewall
vendor: palo model: pan-os
vendor: palo model: networks
db: NVD ids: CVE-2025-0107, CVE-2025-0104, CVE-2025-01037, CVE-2025-01072, CVE-2025-0106, CVE-2025-0103, CVE-2025-01062, CVE-2025-0105, CVE-2025-01052, CVE-2025-01044