VARIoT news about IoT security

Trust: 4.25

Fetched: June 9, 2024, 9:35 a.m., Published: June 4, 2024, midnight
Vulnerabilities: heap corruption, use after free
Affected productsExternal IDs
vendor: google model: chrome
vendor: google model: google chrome
vendor: google model: home
db: NVD ids: CVE-2024-5274, CVE-2024-4947, CVE-2024-4761

Trust: 5.5

Fetched: June 9, 2024, 9:33 a.m., Published: May 13, 2024, 7:49 p.m.
Vulnerabilities: sql injection, denial of service, memory corruption...
Affected productsExternal IDs
vendor: cisco model: small business
vendor: google model: chrome
vendor: citrix model: hypervisor
db: NVD ids: CVE-2023-47610, CVE-2024-26026, CVE-2024-4671, CVE-2023-49606, CVE-2024-21793

Trust: 3.0

Fetched: June 9, 2024, 9:32 a.m., Published: June 5, 2024, 4:59 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: check point model: check point
vendor: check point model: check point vpn

Trust: 4.25

Fetched: June 9, 2024, 9:31 a.m., Published: April 8, 2024, 3 p.m.
Vulnerabilities: authentication bypass, command injection, request forgery...
Affected productsExternal IDs
vendor: cisco model: router
vendor: cisco model: soho
vendor: cisco model: routers
vendor: netgear model: router
vendor: palo model: firewall
vendor: palo model: networks
vendor: palo alto networks model: firewall
vendor: palo alto networks model: networks
db: NVD ids: CVE-2024-21887, CVE-2024-21893, CVE-2023-34362, CVE-2023-46805

Trust: 4.0

Fetched: June 9, 2024, 9:30 a.m., Published: June 9, 2024, midnight
Vulnerabilities: default credentials
Affected productsExternal IDs

Trust: 3.75

Fetched: June 9, 2024, 9:26 a.m., Published: April 9, 2019, midnight
Vulnerabilities: weak password
Affected productsExternal IDs
vendor: apple model: macos

Trust: 3.75

Fetched: June 7, 2024, 9:33 a.m., Published: June 7, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: zyxel model: nas542
vendor: zyxel model: nas326
db: NVD ids: CVE-2024-29973, CVE-2024-29972, CVE-2024-29974

Trust: 3.5

Fetched: June 7, 2024, 9:27 a.m., Published: June 5, 2024, 12:16 p.m.
Vulnerabilities: code execution, buffer overflow
Affected productsExternal IDs
vendor: samsung model: galaxy
vendor: google model: pixel
vendor: google model: android
vendor: oneplus model: one

Trust: 4.0

Fetched: June 7, 2024, 9:26 a.m., Published: May 7, 2024, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2021-26857, CVE-2021-27078, CVE-2021-26858, CVE-2021-26412, CVE-2021-26855, CVE-2021-26854, CVE-2021-27065

Trust: 3.5

Fetched: June 7, 2024, 9:24 a.m., Published: June 4, 2024, midnight
Vulnerabilities: code execution, brute force attack, authentication bypass
Affected productsExternal IDs
vendor: delegate model: delegate

Trust: 5.75

Fetched: June 7, 2024, 9:20 a.m., Published: June 6, 2024, 11:38 a.m.
Vulnerabilities: information disclosure, command injection, code execution
Affected productsExternal IDs
vendor: zyxel model: nas542
vendor: zyxel model: nas326
db: NVD ids: CVE-2024-29973, CVE-2024-29976, CVE-2024-29975, CVE-2024-29974, CVE-2024-29972

Trust: 4.75

Fetched: June 7, 2024, 9:19 a.m., Published: Feb. 13, 2024, 7 p.m.
Vulnerabilities: code execution, command injection, code injection
Affected productsExternal IDs
vendor: zyxel model: nas542
vendor: zyxel model: nas326
db: NVD ids: CVE-2024-29973, CVE-2024-29976, CVE-2024-29975, CVE-2024-29974, CVE-2024-29972

Trust: 5.75

Fetched: June 7, 2024, 9:18 a.m., Published: June 5, 2024, 3:06 p.m.
Vulnerabilities: privilege management vulnerability, code execution, command injection...
Affected productsExternal IDs
vendor: zyxel model: nas542
vendor: zyxel model: nas326
db: NVD ids: CVE-2024-29973, CVE-2024-29976, CVE-2024-29975, CVE-2024-29974, CVE-2024-29972

Trust: 3.5

Fetched: June 7, 2024, 9:17 a.m., Published: May 7, 2024, midnight
Vulnerabilities: path traversal, cross-site scripting, improper access control...
Affected productsExternal IDs
db: NVD ids: CVE-2024-35244, CVE-2024-33610, CVE-2024-34162, CVE-2024-33605, CVE-2024-33616, CVE-2024-36254, CVE-2024-28955, CVE-2024-32151, CVE-2024-28038, CVE-2024-36248, CVE-2024-36251, CVE-2024-29978, CVE-2024-29146, CVE-2024-36249

Trust: 3.5

Fetched: June 7, 2024, 9:16 a.m., Published: Feb. 20, 2023, 7:19 a.m.
Vulnerabilities: code execution, denial of service, privilege escalation
Affected productsExternal IDs
vendor: essential model: phone

Trust: 4.75

Fetched: June 7, 2024, 9:13 a.m., Published: June 6, 2024, 4:47 p.m.
Vulnerabilities: code execution, privilege escalation, code injection
Affected productsExternal IDs
vendor: zyxel model: nas542
vendor: zyxel model: nas326
db: NVD ids: CVE-2024-29973, CVE-2024-29976, CVE-2024-29975, CVE-2024-29974, CVE-2024-29972, CVE-2023-27992
Related entries in the VARIoT vulnerabilities database: VAR-201601-0030

Trust: 3.0

Fetched: June 7, 2024, 9:10 a.m., Published: May 30, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2013-1489, CVE-2016-0778

Trust: 5.25

Fetched: June 7, 2024, 9:10 a.m., Published: June 5, 2024, 10:09 a.m.
Vulnerabilities: code execution, command injection, command execution
Affected productsExternal IDs
vendor: zyxel model: nas542
vendor: zyxel model: nas326
db: NVD ids: CVE-2024-29973, CVE-2024-29976, CVE-2024-29975, CVE-2024-29974, CVE-2024-29972
Related entries in the VARIoT vulnerabilities database: VAR-202002-0458

Trust: 4.75

Fetched: June 7, 2024, 9:08 a.m., Published: Feb. 26, 2020, 3 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: huawei model: hg8245h
vendor: huawei model: huawei
vendor: xiaomi model: redmi
vendor: samsung model: galaxy
vendor: samsung model: galaxy s4
vendor: samsung model: galaxy s8
vendor: samsung model: samsung galaxy
vendor: apple model: iphone
vendor: apple model: apple ipad
vendor: apple model: macos
vendor: apple model: macbook
vendor: apple model: ipad
vendor: apple model: macbook air
vendor: google model: nexus
vendor: google model: android
vendor: asus model: routers
vendor: asus model: wireless routers
vendor: asus model: rt-n12
vendor: asus model: asus
vendor: raspberry pi model: raspberry pi 3
db: NVD ids: CVE-2019-15126

Trust: 5.0

Fetched: June 5, 2024, 9:29 a.m., Published: June 4, 2024, 5:28 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: zyxel model: nas326
vendor: zyxel model: nas542
db: NVD ids: CVE-2024-29974, CVE-2024-29973, CVE-2024-29972