VARIoT news about IoT security

Trust: 3.75

Fetched: Sept. 24, 2024, 10:30 a.m., Published: July 3, 2024, midnight
Vulnerabilities: privilege escalation, directory traversal, path traversal...
Affected productsExternal IDs
db: NVD ids: CVE-2016-6617, CVE-2017-5487, CVE-2016-8870, CVE-2019-8362

Trust: 3.5

Fetched: Sept. 24, 2024, 10:29 a.m., Published: Sept. 24, 2024, midnight
Vulnerabilities: injection attack, sql injection

Trust: 3.5

Fetched: Sept. 24, 2024, 10:28 a.m., Published: Aug. 30, 2024, 4:32 p.m.
Vulnerabilities: privilege escalation, sql injection
Affected productsExternal IDs
db: NVD ids: CVE-2024-43302, CVE-2024-6366, CVE-2024-5057, CVE-2024-7302, CVE-2024-43303, CVE-2024-43286, CVE-2024-43122, CVE-2024-43297, CVE-2024-6725, CVE-2024-5668, CVE-2024-5940, CVE-2024-5763, CVE-2024-2508, CVE-2024-43314, CVE-2024-4367, CVE-2024-43285, CVE-2024-5901, CVE-2024-28000, CVE-2024-43161, CVE-2024-43235, CVE-2024-6208, CVE-2024-5595, CVE-2024-4090, CVE-2024-43162, CVE-2024-6487, CVE-2024-6158, CVE-2024-43298, CVE-2024-39666, CVE-2024-7082, CVE-2024-43119, CVE-2024-43146, CVE-2024-6884, CVE-2024-7092, CVE-2024-7100, CVE-2024-7247, CVE-2024-43231, CVE-2024-7054, CVE-2024-39640, CVE-2024-4483, CVE-2024-7590, CVE-2024-7548, CVE-2024-6692, CVE-2024-7084, CVE-2024-43125, CVE-2024-43118, CVE-2024-43152, CVE-2024-6824, CVE-2024-43142, CVE-2024-5939, CVE-2024-7317
Related entries in the VARIoT vulnerabilities database: VAR-202407-1753

Trust: 4.5

Fetched: Sept. 24, 2024, 10:25 a.m., Published: Aug. 29, 2024, 1:48 p.m.
Vulnerabilities: input validation flaw, input validation vulnerability, code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-42418, CVE-2024-6089, CVE-2024-39776, CVE-2023-34873, CVE-2024-6079

Trust: 4.5

Fetched: Sept. 24, 2024, 10:24 a.m., Published: Sept. 20, 2024, 2:25 p.m.
Vulnerabilities: default credentials, os command injection, brute force attack...
Affected productsExternal IDs
db: NVD ids: CVE-2024-7029, CVE-2024-36401, CVE-2024-7954, CVE-2024-7120, CVE-2024-4577
Related entries in the VARIoT vulnerabilities database: VAR-202409-2108, VAR-202311-0439, VAR-202409-0293, VAR-202409-0257

Trust: 5.5

Fetched: Sept. 24, 2024, 10:23 a.m., Published: Sept. 18, 2024, 7:19 p.m.
Vulnerabilities: injection attack, buffer overflow, use after free...
Affected productsExternal IDs
vendor: rockwell model: factorytalk
vendor: rockwell model: automation factorytalk
vendor: rockwell model: automation factorytalk view site edition
vendor: rockwell model: factorytalk view
vendor: siemens model: simatic pcs 7
vendor: siemens model: wincc
vendor: siemens model: pcs 7
vendor: siemens model: scalance
vendor: siemens model: ruggedcom
vendor: siemens model: simatic pcs neo
vendor: siemens model: scalance m-800
vendor: siemens model: pcs neo
vendor: siemens model: simatic pcs
vendor: siemens model: simatic batch
vendor: siemens model: sinec nms
vendor: siemens model: scalance m-800/s615
vendor: siemens model: process historian
vendor: siemens model: simatic wincc
vendor: siemens model: sinema remote connect
vendor: siemens model: simatic
vendor: siemens model: totally integrated automation portal
vendor: rockwell automation model: factorytalk
vendor: rockwell automation model: automation factorytalk
vendor: rockwell automation model: automation factorytalk view site edition
vendor: rockwell automation model: factorytalk view
db: NVD ids: CVE-2024-45824, CVE-2023-44373, CVE-2023-45852, CVE-2024-45032, CVE-2023-46850, CVE-2023-34873, CVE-2023-5222, CVE-2024-33698, CVE-2024-35783

Trust: 4.5

Fetched: Sept. 24, 2024, 10:22 a.m., Published: -
Vulnerabilities: os command injection, privilege escalation, denial of service...
Affected productsExternal IDs

Trust: 6.0

Fetched: Sept. 24, 2024, 10:22 a.m., Published: Aug. 27, 2024, 4:45 a.m.
Vulnerabilities: heap corruption
Affected productsExternal IDs
vendor: google model: chrome
vendor: google model: google chrome
db: NVD ids: CVE-2024-7965
Related entries in the VARIoT vulnerabilities database: VAR-202408-2695, VAR-202408-2424, VAR-202408-2666, VAR-202408-2536

Trust: 5.5

Fetched: Sept. 24, 2024, 10:21 a.m., Published: -
Vulnerabilities: os command injection, command injection, command execution
Affected productsExternal IDs
vendor: d-link model: dir-846
db: NVD ids: CVE-2024-44341, CVE-2024-44342, CVE-2024-44340, CVE-2024-41622
Related entries in the VARIoT vulnerabilities database: VAR-202409-0992, VAR-202409-0991

Trust: 3.75

Fetched: Sept. 24, 2024, 10:08 a.m., Published: Sept. 24, 2024, midnight
Vulnerabilities: cross-site request forgery, request forgery, cross-site scripting
Affected productsExternal IDs
db: NVD ids: CVE-2024-45836, CVE-2024-45372

Trust: 4.5

Fetched: Sept. 24, 2024, 10:07 a.m., Published: Sept. 18, 2024, 4 p.m.
Vulnerabilities: denial of service, command execution
Affected productsExternal IDs
vendor: draytek model: routers
vendor: hikvision model: hikvision
vendor: hikvision model: ip cameras
vendor: tp-link model: routers
vendor: cisco model: routers
vendor: cisco model: umbrella
vendor: cisco model: soho
vendor: asus model: routers
vendor: asus model: asus
vendor: mikrotik model: routers
vendor: mikrotik model: mikrotik
vendor: canary model: canary

Trust: 3.0

Fetched: Sept. 24, 2024, 10:05 a.m., Published: Sept. 23, 2024, 6:45 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: watch

Trust: 3.25

Fetched: Sept. 24, 2024, 10:04 a.m., Published: -
Vulnerabilities: configuration error
Affected productsExternal IDs

Trust: 3.75

Fetched: Sept. 24, 2024, 10:04 a.m., Published: Sept. 18, 2024, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: google model: pixel
vendor: apple model: tvos
vendor: apple model: iphone
vendor: apple model: macos
vendor: apple model: icloud
vendor: apple model: software update
vendor: apple model: itunes

Trust: 3.25

Fetched: Sept. 24, 2024, 10:02 a.m., Published: Sept. 8, 2024, midnight
Vulnerabilities: configuration error
Affected productsExternal IDs

Trust: 5.0

Fetched: Sept. 24, 2024, 10:01 a.m., Published: Sept. 22, 2024, 5:43 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: sonicwall model: switch
db: NVD ids: CVE-2024-20017
Related entries in the VARIoT vulnerabilities database: VAR-202409-1099, VAR-202409-0703, VAR-202409-1026

Trust: 4.0

Fetched: Sept. 24, 2024, 10 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: d-link model: router
db: NVD ids: CVE-2024-45697, CVE-2024-45695, CVE-2024-45698, CVE-2024-45694, CVE-2024-45696

Trust: 3.0

Fetched: Sept. 24, 2024, 9:59 a.m., Published: Sept. 18, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2024-20685

Trust: 3.75

Fetched: Sept. 24, 2024, 9:59 a.m., Published: Sept. 23, 2024, 5:32 a.m.
Vulnerabilities: cross-site scripting
Affected productsExternal IDs
vendor: apple model: watchos
vendor: apple model: tvos
vendor: apple model: iphone
vendor: apple model: macos
vendor: apple model: safari

Trust: 3.0

Fetched: Sept. 24, 2024, 9:58 a.m., Published: Sept. 23, 2024, 10:45 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: android