VARIoT news about IoT security

Trust: 5.0

Fetched: Oct. 13, 2024, 9:35 a.m., Published: Oct. 11, 2024, 4 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-40711

Trust: 4.5

Fetched: Oct. 13, 2024, 9:33 a.m., Published: Oct. 11, 2024, 3 p.m.
Vulnerabilities: brute force attack, path traversal, command injection...
Affected productsExternal IDs
db: NVD ids: CVE-2024-8963, CVE-2024-8190, CVE-2024-29824

Trust: 5.0

Fetched: Oct. 13, 2024, 9:33 a.m., Published: Oct. 13, 2024, 10:49 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: google model: android

Trust: 3.75

Fetched: Oct. 13, 2024, 9:33 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: samsung model: mobile
vendor: samsung model: samsung
vendor: apple model: iphone
vendor: oneplus model: oneplus
vendor: motorola model: android
vendor: motorola model: motorola
vendor: google model: android
db: NVD ids: CVE-2024-43047

Trust: 4.75

Fetched: Oct. 13, 2024, 9:32 a.m., Published: Oct. 8, 2024, midnight
Vulnerabilities: cross-site request forgery, privilege escalation, request forgery
Affected productsExternal IDs
db: NVD ids: CVE-2024-8458, CVE-2024-8448, CVE-2024-8456

Trust: 3.25

Fetched: Oct. 13, 2024, 9:32 a.m., Published: -
Vulnerabilities: configuration error
Affected productsExternal IDs

Trust: 5.25

Fetched: Oct. 13, 2024, 9:31 a.m., Published: -
Vulnerabilities: os command injection, sql injection, command injection
Affected productsExternal IDs
vendor: palo alto networks model: firewall
vendor: palo alto networks model: networks
vendor: palo alto networks model: pan-os
vendor: paloaltonetworks model: firewall
vendor: paloaltonetworks model: networks
vendor: paloaltonetworks model: pan-os
vendor: palo model: firewall
vendor: palo model: networks
vendor: palo model: pan-os
db: NVD ids: CVE-2024-9467, CVE-2024-9466, CVE-2024-9463, CVE-2024-9465, CVE-2024-9464, CVE-2024-5910
Related entries in the VARIoT vulnerabilities database: VAR-202409-0028, VAR-202409-0034

Trust: 4.75

Fetched: Oct. 13, 2024, 9:30 a.m., Published: Sept. 5, 2024, 6:23 a.m.
Vulnerabilities: privilege escalation, denial of service
Affected productsExternal IDs
vendor: google model: android
db: NVD ids: CVE-2024-40655, CVE-2024-3655, CVE-2024-40656, CVE-2024-39432, CVE-2024-40658, CVE-2024-40657, CVE-2024-23358, CVE-2024-33052, CVE-2024-40654, CVE-2024-39431, CVE-2024-23362, CVE-2024-23359, CVE-2024-40662, CVE-2024-40650, CVE-2024-31336, CVE-2024-32896, CVE-2024-36972, CVE-2024-40659, CVE-2024-40652, CVE-2024-23716, CVE-2024-33042
Related entries in the VARIoT vulnerabilities database: VAR-202212-1132

Trust: 4.75

Fetched: Oct. 13, 2024, 9:29 a.m., Published: Aug. 22, 2024, 9 a.m.
Vulnerabilities: buffer overflow
Affected productsExternal IDs
vendor: fortigate model: fortios
db: NVD ids: CVE-2022-42475

Trust: 3.75

Fetched: Oct. 13, 2024, 9:28 a.m., Published: July 17, 2024, 4:45 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: android
vendor: apple model: watchos
vendor: apple model: macos
vendor: apple model: iphone
vendor: apple model: tvos
db: NVD ids: CVE-2023-45866, CVE-2020-0556

Trust: 5.25

Fetched: Oct. 13, 2024, 9:28 a.m., Published: Oct. 11, 2024, 8:24 p.m.
Vulnerabilities: memory corruption
Affected productsExternal IDs
db: NVD ids: CVE-2024-43047, CVE-2024-33066

Trust: 3.5

Fetched: Oct. 13, 2024, 9:27 a.m., Published: July 11, 2024, 6:43 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: asus model: asus
vendor: asus model: router
vendor: google model: home
vendor: google model: android
vendor: apple model: software update
db: NVD ids: CVE-2024-31497

Trust: 5.5

Fetched: Oct. 13, 2024, 9:26 a.m., Published: Sept. 13, 2024, midnight
Vulnerabilities: information disclosure, code execution, denial of service
Affected productsExternal IDs
vendor: google model: wifi
vendor: google model: home
vendor: google model: wifi router
db: NVD ids: CVE-2024-44097, CVE-2023-45853, CVE-2024-22013

Trust: 4.25

Fetched: Oct. 13, 2024, 9:21 a.m., Published: July 25, 2024, 2:55 a.m.
Vulnerabilities: code execution, command injection, request forgery
Affected productsExternal IDs
vendor: cisco model: firepower
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: asa software
vendor: cisco model: adaptive security appliance
vendor: cisco model: firepower threat defense
vendor: palo alto networks model: networks
vendor: palo alto networks model: firewall
vendor: palo alto networks model: ssl vpn
vendor: palo model: networks
vendor: palo model: firewall
vendor: palo model: ssl vpn
db: NVD ids: CVE-2024-23313, CVE-2024-21893, CVE-2024-3400, CVE-2024-20359, CVE-2024-20353, CVE-2024-21762, CVE-2024-20358

Trust: 3.0

Fetched: Oct. 13, 2024, 9:19 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: samsung model: samsung

Trust: 3.0

Fetched: Oct. 11, 2024, 10:37 a.m., Published: Sept. 19, 2024, 9:42 a.m.
Vulnerabilities: privilege escalation, code execution, access control vulnerability...
Affected productsExternal IDs
db: NVD ids: CVE-2019-1069, CVE-2024-27348, CVE-2020-0618, CVE-2022-21445, CVE-2020-14644
Related entries in the VARIoT vulnerabilities database: VAR-202409-0292

Trust: 4.75

Fetched: Oct. 11, 2024, 10:29 a.m., Published: Sept. 17, 2024, 3:19 p.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: siemens model: simatic s7-200 smart cpu cr60
vendor: siemens model: simatic s7-200 smart cpu
vendor: siemens model: simatic s7-200 smart cpu st40
vendor: siemens model: simatic s7-200 smart cpu st30
vendor: siemens model: simatic s7-200 smart cpu st20
vendor: siemens model: simatic s7-200 smart cpu cr40
vendor: siemens model: simatic s7-200 smart cpu st60
vendor: siemens model: simatic s7-200 smart cpu sr30
vendor: siemens model: simatic s7-200
vendor: siemens model: simatic s7-200 smart cpu sr20
vendor: siemens model: simatic s7-200 smart
vendor: siemens model: simatic s7-200 smart cpu sr60
vendor: siemens model: s7-200 smart
vendor: siemens model: simatic s7-200 smart cpu sr40
vendor: siemens model: simatic
db: NVD ids: CVE-2024-43647
Related entries in the VARIoT vulnerabilities database: VAR-202410-0128

Trust: 3.5

Fetched: Oct. 11, 2024, 10:17 a.m., Published: Oct. 11, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: siemens model: sentron pac3200
vendor: siemens model: modbus tcp
db: NVD ids: CVE-2024-41798

Trust: 5.0

Fetched: Oct. 11, 2024, 10:15 a.m., Published: Sept. 19, 2024, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-7490

Trust: 3.75

Fetched: Oct. 11, 2024, 10:02 a.m., Published: Oct. 10, 2024, 8:06 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: oneplus model: oneplus
vendor: motorola model: android
vendor: motorola model: motorola
vendor: samsung model: mobile devices
vendor: samsung model: mobile
vendor: samsung model: samsung
db: NVD ids: CVE-2024-43047