VARIoT news about IoT security

Trust: 3.75

Fetched: March 22, 2024, 9:41 a.m., Published: March 6, 2024, 12:47 p.m.
Vulnerabilities: session hijacking, cross-site scripting, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2023-0846

Trust: 4.25

Fetched: March 22, 2024, 9:39 a.m., Published: -
Vulnerabilities: default password
Affected productsExternal IDs

Trust: 3.0

Fetched: March 22, 2024, 9:38 a.m., Published: March 2, 2024, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-21762
Related entries in the VARIoT vulnerabilities database: VAR-202402-1535, VAR-202402-1534, VAR-202402-1774

Trust: 4.75

Fetched: March 22, 2024, 9:36 a.m., Published: Feb. 13, 2024, 8:22 p.m.
Vulnerabilities: code execution, cross-site scripting, security feature bypass...
Affected productsExternal IDs
db: NVD ids: CVE-2024-21396, CVE-2024-21355, CVE-2024-21329, CVE-2024-21402, CVE-2024-21363, CVE-2024-21389, CVE-2024-21338, CVE-2024-21380, CVE-2024-21369, CVE-2024-21397, CVE-2024-21339, CVE-2024-21340, CVE-2024-21327, CVE-2024-21381, CVE-2024-21366, CVE-2024-21384, CVE-2024-21357, CVE-2024-21367, CVE-2024-21353, CVE-2024-21345, CVE-2024-21405, CVE-2024-21315, CVE-2024-21358, CVE-2024-21410, CVE-2024-21350, CVE-2024-21401, CVE-2024-21364, CVE-2024-21368, CVE-2024-21365, CVE-2024-21328, CVE-2024-21348, CVE-2024-20679, CVE-2024-21356, CVE-2024-21359, CVE-2024-21362, CVE-2024-21413, CVE-2024-21420, CVE-2024-21349, CVE-2024-21354, CVE-2024-21377, CVE-2024-21360, CVE-2024-21371, CVE-2024-20695, CVE-2024-21346, CVE-2024-21379, CVE-2024-21347, CVE-2024-21412, CVE-2024-21342, CVE-2024-21395, CVE-2024-21344, CVE-2024-21361, CVE-2024-21406, CVE-2024-20667, CVE-2024-21386, CVE-2024-20673, CVE-2024-21374, CVE-2024-21394, CVE-2024-21403, CVE-2024-21352, CVE-2024-21375, CVE-2024-21343, CVE-2024-21351, CVE-2024-21391, CVE-2024-21393, CVE-2024-21341, CVE-2024-21370, CVE-2024-21404, CVE-2024-21372, CVE-2024-20684, CVE-2024-21378, CVE-2024-21304, CVE-2024-21376

Trust: 4.25

Fetched: March 22, 2024, 9:35 a.m., Published: -
Vulnerabilities: default password
Affected productsExternal IDs

Trust: 3.5

Fetched: March 22, 2024, 9:32 a.m., Published: Feb. 29, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: pulse secure model: policy secure
vendor: pulse secure model: connect secure
db: NVD ids: CVE-2023-46805, CVE-2024-21893, CVE-2024-21887, CVE-2024-2204

Trust: 3.5

Fetched: March 22, 2024, 9:32 a.m., Published: March 19, 2024, 6:32 a.m.
Vulnerabilities: denial of service, improper validation
Affected productsExternal IDs
vendor: apple model: ipad air
vendor: apple model: iphone
vendor: apple model: webkit
vendor: apple model: ipad
vendor: apple model: safari

Trust: 3.0

Fetched: March 22, 2024, 9:32 a.m., Published: March 22, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2024-21762

Trust: 3.25

Fetched: March 22, 2024, 9:28 a.m., Published: March 6, 2024, midnight
Vulnerabilities: command injection
Affected productsExternal IDs

Trust: 3.0

Fetched: March 22, 2024, 9:24 a.m., Published: March 13, 2024, 3:14 p.m.
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2024-21900, CVE-2024-21901, CVE-2024-21899

Trust: 3.25

Fetched: March 22, 2024, 9:21 a.m., Published: March 13, 2024, 5:14 a.m.
Vulnerabilities: cross-site scripting, sql injection
Affected productsExternal IDs
vendor: snort model: snort
vendor: zoho model: manageengine vulnerability manager plus
vendor: tripwire model: ip360
vendor: google model: wifi

Trust: 3.5

Fetched: March 22, 2024, 9:12 a.m., Published: March 22, 2022, midnight
Vulnerabilities: privilege escalation, denial of service

Trust: 3.0

Fetched: March 22, 2024, 9:11 a.m., Published: -
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-21429
Related entries in the VARIoT vulnerabilities database: VAR-202212-1132

Trust: 3.75

Fetched: March 20, 2024, 9:23 a.m., Published: March 20, 2024, 8:30 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: fortigate model: fortios
db: NVD ids: CVE-2022-42475, CVE-2024-21762

Trust: 4.75

Fetched: March 20, 2024, 9:18 a.m., Published: March 20, 2024, 7:52 a.m.
Vulnerabilities: improper validation
Affected productsExternal IDs
vendor: apple model: safari
vendor: apple model: iphone
vendor: apple model: ipad
vendor: apple model: ipad air
vendor: apple model: webkit
Related entries in the VARIoT vulnerabilities database: VAR-202210-0198, VAR-202403-2416

Trust: 4.75

Fetched: March 19, 2024, 9:18 a.m., Published: -
Vulnerabilities: code execution, buffer overflow, authentication bypass...
Affected productsExternal IDs
vendor: fortigate model: fortios
db: NVD ids: CVE-2024-21762, CVE-2022-40684, CVE-2023-27997, CVE-2023-48788

Trust: 3.5

Fetched: March 19, 2024, 9:17 a.m., Published: Dec. 27, 2021, 10:13 a.m.
Vulnerabilities: code execution, buffer overflow, privilege escalation...
Affected productsExternal IDs

Trust: 3.0

Fetched: March 19, 2024, 9:11 a.m., Published: March 25, 2018, 6:02 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: identity services engine
vendor: cisco model: cisco identity services engine
Related entries in the VARIoT vulnerabilities database: VAR-202003-1707

Trust: 4.25

Fetched: March 19, 2024, 9:06 a.m., Published: -
Vulnerabilities: default credentials, denial of service
Affected productsExternal IDs
vendor: trend model: security
vendor: trend model: internet security
vendor: trend model: home network security
vendor: trend micro model: security
vendor: trend micro model: internet security
vendor: trend micro model: home network security
vendor: sonos model: sonos
db: NVD ids: CVE-2020-9054

Trust: 3.5

Fetched: March 15, 2024, 9:13 a.m., Published: March 6, 2024, 8:19 p.m.
Vulnerabilities: information disclosure, code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-22253, CVE-2024-22254, CVE-2024-22252, CVE-2024-22255