VARIoT news about IoT security

Trust: 4.25

Fetched: March 13, 2024, 9:30 a.m., Published: Dec. 14, 2023, midnight
Vulnerabilities: session hijacking, buffer overflow
Affected productsExternal IDs
vendor: palo alto networks model: networks
vendor: palo model: networks
vendor: citrix model: gateway
vendor: citrix model: netscaler adc
vendor: citrix model: netscaler
vendor: citrix model: netscaler gateway
vendor: citrix model: netscaler application delivery controller
vendor: citrix model: application delivery controller
db: NVD ids: CVE-2023-4966, CVE-2023-4967
Related entries in the VARIoT vulnerabilities database: VAR-202310-0175

Trust: 5.0

Fetched: March 13, 2024, 9:30 a.m., Published: Feb. 8, 2024, 11:11 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: fortigate model: fortios
db: NVD ids: CVE-2024-23113, CVE-2023-47537, CVE-2023-44487, CVE-2024-21762

Trust: 3.0

Fetched: March 13, 2024, 9:24 a.m., Published: Feb. 9, 2024, 6:13 p.m.
Vulnerabilities: entity injection
Affected productsExternal IDs
db: NVD ids: CVE-2024-22024

Trust: 3.0

Fetched: March 12, 2024, 9:33 a.m., Published: March 18, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2024-23836

Trust: 6.0

Fetched: March 12, 2024, 9:33 a.m., Published: -
Vulnerabilities: privilege escalation, information disclosure, input validation issue...
Affected productsExternal IDs
vendor: zoom model: client
db: NVD ids: CVE-2024-24695, CVE-2024-24697, CVE-2024-24690, CVE-2024-24698, CVE-2024-24691, CVE-2024-24696, CVE-2024-24699

Trust: 5.0

Fetched: March 12, 2024, 9:32 a.m., Published: March 12, 2024, midnight
Vulnerabilities: memory corruption, code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-27099

Trust: 3.0

Fetched: March 12, 2024, 9:26 a.m., Published: June 14, 2023, 6 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: check point model: check point

Trust: 5.25

Fetched: March 12, 2024, 9:23 a.m., Published: March 12, 2024, 5:24 a.m.
Vulnerabilities: sql injection
Affected productsExternal IDs
db: NVD ids: CVE-2024-21900, CVE-2024-21899, CVE-2024-21901

Trust: 3.5

Fetched: March 12, 2024, 9:22 a.m., Published: Feb. 27, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: home

Trust: 4.25

Fetched: March 12, 2024, 9:22 a.m., Published: March 12, 2024, 7:26 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-21762

Trust: 5.0

Fetched: March 12, 2024, 9:21 a.m., Published: March 7, 2024, 12:19 a.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
db: NVD ids: CVE-2024-27198

Trust: 3.75

Fetched: March 12, 2024, 9:21 a.m., Published: March 11, 2024, midnight
Vulnerabilities: authentication bug, sql injection
Affected productsExternal IDs
db: NVD ids: CVE-2024-21900, CVE-2024-21899, CVE-2024-21901

Trust: 3.0

Fetched: March 12, 2024, 9:20 a.m., Published: March 10, 2024, 3:30 a.m.
Vulnerabilities: command injection
Affected productsExternal IDs
Related entries in the VARIoT vulnerabilities database: VAR-202208-1345, VAR-202208-1294

Trust: 4.75

Fetched: March 12, 2024, 9:19 a.m., Published: March 6, 2024, 1:41 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: apple model: macos
vendor: apple model: webkit
vendor: apple model: safari
vendor: apple model: ipad
db: NVD ids: CVE-2022-32893, CVE-2022-32894, CVE-2023-37450

Trust: 4.25

Fetched: March 12, 2024, 9:18 a.m., Published: March 6, 2024, 5:15 p.m.
Vulnerabilities: directory traversal
Affected productsExternal IDs

Trust: 5.0

Fetched: March 12, 2024, 9:18 a.m., Published: March 6, 2024, 5:15 p.m.
Vulnerabilities: command injection
Affected productsExternal IDs
vendor: cisco model: cisco small business
vendor: cisco model: small business
vendor: cisco model: series

Trust: 5.0

Fetched: March 12, 2024, 9:17 a.m., Published: March 11, 2024, 4:01 p.m.
Vulnerabilities: code injection, arbitrary command execution, command execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-21900, CVE-2024-21899, CVE-2024-21901

Trust: 5.0

Fetched: March 12, 2024, 9:16 a.m., Published: -
Vulnerabilities: sql injection, authentication vulnerability
Affected productsExternal IDs
db: NVD ids: CVE-2024-21900, CVE-2024-21899, CVE-2024-21901
Related entries in the VARIoT vulnerabilities database: VAR-202203-0043

Trust: 5.0

Fetched: March 10, 2024, 10:47 a.m., Published: March 9, 2022, 6:20 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: pure model: purity
db: NVD ids: CVE-2022-0847

Trust: 5.0

Fetched: March 10, 2024, 10:46 a.m., Published: March 1, 2024, 2:36 p.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: google model: android
db: NVD ids: CVE-2023-52160, CVE-2023-52161