VARIoT news about IoT security

Trust: 4.25

Fetched: Oct. 2, 2024, 11:56 a.m., Published: Oct. 1, 2024, midnight
Vulnerabilities: cross-site scripting, session hijacking, code execution
Affected productsExternal IDs
vendor: pulp model: pulp
vendor: sony model: playstation
db: NVD ids: CVE-2024-22170

Trust: 3.0

Fetched: Oct. 2, 2024, 11:54 a.m., Published: Oct. 1, 2024, 12:54 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: anviz model: anviz

Trust: 3.0

Fetched: Oct. 2, 2024, 11:53 a.m., Published: Sept. 18, 2024, 7:12 a.m.
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2024-46743

Trust: 3.75

Fetched: Oct. 2, 2024, 11:46 a.m., Published: Sept. 27, 2024, 3:19 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: cups model: cups
vendor: apple model: macos
vendor: apple model: cups
db: NVD ids: CVE-2024-47177, CVE-2024-47176, CVE-2024-47175

Trust: 3.0

Fetched: Oct. 2, 2024, 11:46 a.m., Published: Sept. 26, 2024, 4 a.m.
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2022-29871

Trust: 5.25

Fetched: Oct. 2, 2024, 11:45 a.m., Published: Sept. 20, 2024, 5:50 p.m.
Vulnerabilities: information leak
Affected productsExternal IDs
db: NVD ids: CVE-2024-8612

Trust: 3.0

Fetched: Oct. 2, 2024, 11:45 a.m., Published: Oct. 1, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2024-47524

Trust: 4.0

Fetched: Oct. 2, 2024, 11:44 a.m., Published: Oct. 2, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: essential model: phone

Trust: 3.5

Fetched: Oct. 2, 2024, 11:44 a.m., Published: Oct. 1, 2024, 1 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: mesh model: mesh

Trust: 4.5

Fetched: Oct. 2, 2024, 11:44 a.m., Published: Sept. 4, 2024, 6:57 p.m.
Vulnerabilities: cross-site scripting, pointer dereference vulnerability, command injection...
Affected productsExternal IDs
db: NVD ids: CVE-2024-42059, CVE-2024-6343, CVE-2024-42060, CVE-2024-42061, CVE-2024-5412, CVE-2024-7203, CVE-2024-42057, CVE-2024-7261, CVE-2024-42058

Trust: 5.5

Fetched: Oct. 2, 2024, 11:43 a.m., Published: Oct. 2, 2024, 6:22 a.m.
Vulnerabilities: code execution, command execution, arbitrary command execution...
Affected productsExternal IDs
vendor: cups model: cups
db: NVD ids: CVE-2024-47177, CVE-2024-47076, CVE-2024-47176, CVE-2024-47175

Trust: 3.25

Fetched: Oct. 2, 2024, 11:41 a.m., Published: Oct. 1, 2024, 6 p.m.
Vulnerabilities: injection attack, sql injection
Affected productsExternal IDs
vendor: palo model: firewall
vendor: palo model: networks
vendor: palo alto networks model: firewall
vendor: palo alto networks model: networks

Trust: 5.5

Fetched: Oct. 2, 2024, 11:38 a.m., Published: Oct. 2, 2024, midnight
Vulnerabilities: code execution, command execution, arbitrary command execution...
Affected productsExternal IDs
vendor: cups model: cups
db: NVD ids: CVE-2024-47177, CVE-2024-47076, CVE-2024-47176, CVE-2024-47175

Trust: 5.25

Fetched: Oct. 2, 2024, 11:36 a.m., Published: Oct. 1, 2024, midnight
Vulnerabilities: cross-site scripting
Affected productsExternal IDs
db: NVD ids: CVE-2024-47524

Trust: 5.75

Fetched: Oct. 2, 2024, 11:36 a.m., Published: Oct. 12, 2024, midnight
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: apple model: macos
vendor: apple model: ipad
db: NVD ids: CVE-2023-42861, CVE-2024-27796, CVE-2024-27842, CVE-2024-23288

Trust: 4.5

Fetched: Oct. 2, 2024, 11:35 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: lexmark model: lexmark
db: NVD ids: CVE-2022-29850

Trust: 4.5

Fetched: Oct. 2, 2024, 11:34 a.m., Published: Sept. 17, 2024, 11:08 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: imagemagick model: imagemagick
vendor: delegate model: delegate
db: NVD ids: CVE-2016-3714

Trust: 3.0

Fetched: Oct. 2, 2024, 11:34 a.m., Published: Sept. 27, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: ios xe software
vendor: cisco model: cisco ios xe
vendor: cisco model: cisco ios
vendor: cisco model: ios xe
Related entries in the VARIoT vulnerabilities database: VAR-202006-1056

Trust: 5.5

Fetched: Oct. 2, 2024, 11:33 a.m., Published: Feb. 13, 2024, 7 p.m.
Vulnerabilities: pointer dereference flaw, privilege escalation, command execution
Affected productsExternal IDs
vendor: palo model: networks
vendor: draytek model: vigor3900
vendor: draytek model: vigor2960
vendor: draytek model: vigor300b
vendor: draytek model: routers
vendor: palo alto networks model: networks
vendor: d-link model: dir-820l
vendor: d-link model: router
db: NVD ids: CVE-2021-4043, CVE-2023-25280, CVE-2019-0344, CVE-2020-15415

Trust: 5.5

Fetched: Oct. 2, 2024, 11:26 a.m., Published: Sept. 27, 2024, 12:46 p.m.
Vulnerabilities: improper validation, command execution, arbitrary command execution...
Affected productsExternal IDs
vendor: cups model: cups
db: NVD ids: CVE-2024-47177, CVE-2024-47076, CVE-2024-47176, CVE-2024-47175