VARIoT news about IoT security

Trust: 5.75

Fetched: Oct. 2, 2024, 11:36 a.m., Published: Oct. 12, 2024, midnight
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: apple model: macos
vendor: apple model: ipad
db: NVD ids: CVE-2023-42861, CVE-2024-27796, CVE-2024-27842, CVE-2024-23288

Trust: 4.5

Fetched: Oct. 2, 2024, 11:35 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: lexmark model: lexmark
db: NVD ids: CVE-2022-29850

Trust: 4.5

Fetched: Oct. 2, 2024, 11:34 a.m., Published: Sept. 17, 2024, 11:08 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: imagemagick model: imagemagick
vendor: delegate model: delegate
db: NVD ids: CVE-2016-3714

Trust: 3.0

Fetched: Oct. 2, 2024, 11:34 a.m., Published: Sept. 27, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: ios xe software
vendor: cisco model: cisco ios xe
vendor: cisco model: cisco ios
vendor: cisco model: ios xe
Related entries in the VARIoT vulnerabilities database: VAR-202006-1056

Trust: 5.5

Fetched: Oct. 2, 2024, 11:33 a.m., Published: Feb. 13, 2024, 7 p.m.
Vulnerabilities: pointer dereference flaw, privilege escalation, command execution
Affected productsExternal IDs
vendor: palo model: networks
vendor: draytek model: vigor3900
vendor: draytek model: vigor2960
vendor: draytek model: vigor300b
vendor: draytek model: routers
vendor: palo alto networks model: networks
vendor: d-link model: dir-820l
vendor: d-link model: router
db: NVD ids: CVE-2021-4043, CVE-2023-25280, CVE-2019-0344, CVE-2020-15415

Trust: 5.5

Fetched: Oct. 2, 2024, 11:26 a.m., Published: Sept. 27, 2024, 12:46 p.m.
Vulnerabilities: improper validation, command execution, arbitrary command execution...
Affected productsExternal IDs
vendor: cups model: cups
db: NVD ids: CVE-2024-47177, CVE-2024-47076, CVE-2024-47176, CVE-2024-47175

Trust: 4.5

Fetched: Oct. 2, 2024, 11:25 a.m., Published: July 12, 2024, 9 a.m.
Vulnerabilities: session hijacking, default credentials
Affected productsExternal IDs
vendor: trend model: security
db: NVD ids: CVE-2023-31222

Trust: 4.75

Fetched: Oct. 2, 2024, 11:25 a.m., Published: Aug. 5, 2024, 6:39 a.m.
Vulnerabilities: security bypass
Affected productsExternal IDs
vendor: rockwell automation model: 1756-en2f series
vendor: rockwell automation model: 1756-en3tr series b
vendor: rockwell automation model: controllogix 5580
vendor: rockwell automation model: 1756-en3tr series
vendor: rockwell automation model: guardlogix
vendor: rockwell automation model: 1756-en2tr series
vendor: rockwell automation model: 1756-en2t series
vendor: rockwell automation model: 1756-en2f series c
vendor: rockwell automation model: controllogix
vendor: rockwell automation model: automation controllogix
vendor: rockwell automation model: 1756-en2tr series c
vendor: rockwell automation model: controllogix controllers
vendor: rockwell model: 1756-en2f series
vendor: rockwell model: 1756-en3tr series b
vendor: rockwell model: controllogix 5580
vendor: rockwell model: 1756-en3tr series
vendor: rockwell model: guardlogix
vendor: rockwell model: 1756-en2tr series
vendor: rockwell model: 1756-en2t series
vendor: rockwell model: 1756-en2f series c
vendor: rockwell model: controllogix
vendor: rockwell model: automation controllogix
vendor: rockwell model: 1756-en2tr series c
vendor: rockwell model: controllogix controllers
db: NVD ids: CVE-2024-6242

Trust: 5.0

Fetched: Oct. 2, 2024, 11:24 a.m., Published: May 2, 2024, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-21416

Trust: 3.5

Fetched: Oct. 2, 2024, 11:23 a.m., Published: Sept. 27, 2024, 8:52 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: safari
vendor: palo model: firewall
vendor: palo model: networks
vendor: google model: google chrome
vendor: google model: chrome
vendor: palo alto networks model: firewall
vendor: palo alto networks model: networks

Trust: 3.25

Fetched: Oct. 2, 2024, 11:22 a.m., Published: Oct. 2, 3581, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: dell model: bios

Trust: 3.75

Fetched: Oct. 2, 2024, 11:22 a.m., Published: Sept. 27, 2024, 3:19 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: cups model: cups
vendor: apple model: macos
vendor: apple model: cups
db: NVD ids: CVE-2024-47177, CVE-2024-47176, CVE-2024-47175

Trust: 5.5

Fetched: Oct. 2, 2024, 11:21 a.m., Published: Aug. 6, 2024, 6:12 a.m.
Vulnerabilities: privilege escalation, information disclosure, code execution
Affected productsExternal IDs
vendor: google model: pixel
vendor: google model: android
db: NVD ids: CVE-2024-29748, CVE-2024-32896, CVE-2018-0824, CVE-2024-36971, CVE-2024-29745

Trust: 3.5

Fetched: Oct. 2, 2024, 11:21 a.m., Published: Aug. 22, 2023, 2:16 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: wifi
vendor: google model: home

Trust: 4.5

Fetched: Oct. 2, 2024, 11:18 a.m., Published: Aug. 16, 2024, 12:53 p.m.
Vulnerabilities: code injection, code execution
Affected productsExternal IDs
vendor: essential model: phone
vendor: google model: pixel
vendor: google model: android
Related entries in the VARIoT vulnerabilities database: VAR-202112-0566, VAR-202112-0562, VAR-202112-1782

Trust: 3.75

Fetched: Oct. 2, 2024, 11:18 a.m., Published: Sept. 13, 2024, 12:45 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-23652, CVE-2024-24557, CVE-2024-23651, CVE-2024-8696, CVE-2024-23653, CVE-2024-8695, CVE-2021-44228, CVE-2021-45046, CVE-2024-21626, CVE-2021-45105, CVE-2024-23650, CVE-2022-42889

Trust: 3.75

Fetched: Oct. 2, 2024, 11:17 a.m., Published: Sept. 7, 2017, 9:51 a.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: cisco model: routers

Trust: 3.5

Fetched: Oct. 2, 2024, 11:16 a.m., Published: June 30, 2021, 3:33 p.m.
Vulnerabilities: sql injection, configuration vulnerability
Affected productsExternal IDs
Related entries in the VARIoT vulnerabilities database: VAR-202408-0167

Trust: 5.25

Fetched: Oct. 2, 2024, 11:14 a.m., Published: Aug. 7, 2024, 3:15 p.m.
Vulnerabilities: buffer overflow
Affected productsExternal IDs
db: NVD ids: CVE-2024-7581

Trust: 3.75

Fetched: Oct. 2, 2024, 11:14 a.m., Published: Sept. 4, 2024, 11:19 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: yubico model: yubihsm 2
vendor: yubico model: yubikey