VARIoT news about IoT security

Trust: 3.25

Fetched: May 8, 2024, 9:07 a.m., Published: May 1, 2024, midnight
Vulnerabilities: code execution, path traversal
Affected productsExternal IDs
vendor: google model: android
vendor: google model: home
vendor: xiaomi model: browser

Trust: 3.75

Fetched: May 7, 2024, 9:40 a.m., Published: May 7, 2024, midnight
Vulnerabilities: default credentials
Affected productsExternal IDs

Trust: 4.0

Fetched: May 7, 2024, 9:39 a.m., Published: -
Vulnerabilities: privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2022-38028, CVE-2023-23397

Trust: 5.25

Fetched: May 7, 2024, 9:39 a.m., Published: May 6, 2024, 11:47 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: google model: android
Related entries in the VARIoT vulnerabilities database: VAR-202404-0069, VAR-202404-0070

Trust: 4.75

Fetched: May 7, 2024, 9:37 a.m., Published: April 9, 2024, 7:27 a.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: d-link model: dns-327l
vendor: d-link model: dns-320l
vendor: d-link model: dns-325
vendor: d-link model: dns-340l
db: NVD ids: CVE-2024-3272, CVE-2024-3273

Trust: 4.75

Fetched: May 7, 2024, 9:36 a.m., Published: May 6, 2024, 7:54 a.m.
Vulnerabilities: path traversal
Affected productsExternal IDs
vendor: google model: home
vendor: google model: android

Trust: 3.0

Fetched: May 7, 2024, 9:36 a.m., Published: April 22, 2024, 7:23 p.m.
Vulnerabilities: -
Affected productsExternal IDs
Related entries in the VARIoT vulnerabilities database: VAR-202404-0069, VAR-202404-0070

Trust: 4.25

Fetched: May 7, 2024, 9:30 a.m., Published: April 15, 2024, midnight
Vulnerabilities: privilege elevation, script execution
Affected productsExternal IDs
vendor: palo model: networks globalprotect
vendor: palo model: pan-os
vendor: palo model: networks
vendor: palo model: firewall
vendor: palo model: palo alto networks globalprotect
vendor: palo alto networks model: networks globalprotect
vendor: palo alto networks model: pan-os
vendor: palo alto networks model: networks
vendor: palo alto networks model: firewall
vendor: palo alto networks model: palo alto networks globalprotect
db: NVD ids: CVE-2024-3272, CVE-2024-3273

Trust: 4.5

Fetched: May 7, 2024, 9:29 a.m., Published: April 22, 2024, 8:42 a.m.
Vulnerabilities: denial of service, session hijacking
Affected productsExternal IDs
vendor: wireshark model: wireshark

Trust: 3.5

Fetched: May 7, 2024, 9:29 a.m., Published: April 24, 2024, 11:32 p.m.
Vulnerabilities: cross-site request forgery, cross-site scripting, code injection...
Affected productsExternal IDs

Trust: 4.75

Fetched: May 7, 2024, 9:28 a.m., Published: May 6, 2024, 8:28 p.m.
Vulnerabilities: memory corruption, command injection
Affected productsExternal IDs
vendor: xiaomi model: miui

Trust: 3.0

Fetched: May 7, 2024, 9:26 a.m., Published: May 7, 2024, 7:01 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: android

Trust: 5.5

Fetched: May 7, 2024, 9:26 a.m., Published: April 11, 2024, 8:23 a.m.
Vulnerabilities: security feature bypass, feature bypass
Affected productsExternal IDs
vendor: google model: chrome
vendor: google model: android
db: NVD ids: CVE-2024-29988, CVE-2024-26234

Trust: 5.0

Fetched: May 7, 2024, 9:25 a.m., Published: April 28, 2024, midnight
Vulnerabilities: sql injection
Affected productsExternal IDs
vendor: cisco model: firepower
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: adaptive security appliance
vendor: cisco model: firepower threat defense
db: NVD ids: CVE-2024-27956

Trust: 4.5

Fetched: May 7, 2024, 9:23 a.m., Published: April 10, 2024, 8:34 a.m.
Vulnerabilities: command execution, information exposure, arbitrary command execution...
Affected productsExternal IDs
db: NVD ids: CVE-2024-23662, CVE-2023-48784, CVE-2023-41677
Related entries in the VARIoT vulnerabilities database: VAR-202404-0069, VAR-202404-0070

Trust: 4.25

Fetched: May 7, 2024, 9:21 a.m., Published: April 16, 2024, 12:53 p.m.
Vulnerabilities: injection attack, command injection, code execution
Affected productsExternal IDs
vendor: d-link model: dns-327l
vendor: d-link model: dns-320l
vendor: d-link model: dns-325
vendor: d-link model: dns-340l
db: NVD ids: CVE-2024-3272, CVE-2024-3273

Trust: 5.5

Fetched: May 7, 2024, 9:19 a.m., Published: May 5, 2024, midnight
Vulnerabilities: command execution
Affected productsExternal IDs
vendor: palo model: pan-os
vendor: palo model: firewall
vendor: palo model: networks
vendor: palo alto networks model: pan-os
vendor: palo alto networks model: firewall
vendor: palo alto networks model: networks
db: NVD ids: CVE-2024-3400

Trust: 3.25

Fetched: May 7, 2024, 9:19 a.m., Published: April 25, 2024, midnight
Vulnerabilities: command injection
Affected productsExternal IDs

Trust: 3.75

Fetched: May 7, 2024, 9:17 a.m., Published: April 28, 2024, 3:35 a.m.
Vulnerabilities: improper validation, command injection, denial of service...
Affected productsExternal IDs
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: firepower
vendor: cisco model: adaptive security appliance
vendor: cisco model: firepower threat defense

Trust: 4.75

Fetched: May 7, 2024, 9:16 a.m., Published: April 10, 2024, 1:51 p.m.
Vulnerabilities: calculation error
Affected productsExternal IDs
vendor: asus model: asus
vendor: lenovo model: updates
vendor: lenovo model: system
db: NVD ids: CVE-2023-40238